I can't use the web-interface from the master-server. I can open the website but i see only a white page. One the replica-server i can use the web-interface without a problem. Also i get an error from ipa-ods-exporter about "Public key with same ID already exists", this problem start after i remove the dnssec service and reinstall it on the master-server.
Bevor i removed the dnssec-service i have remove over the replica-web-interface all dnssec-entries.
I can't because i don't know the cause.
I think the problem start after a update but i don't know itexactly.
web-interface is not available and dnssec issue
web-interface is available and no dnssec errors
$uname -r 4.18.0-240.1.1.el8_3.x86_64
$ rpm -q freeipa-server freeipa-client ipa-server ipa-client 389-ds-base pki-ca krb5-server package freeipa-server is not installed package freeipa-client is not installed ipa-server-4.8.7-13.module_el8.3.0+606+1e8766d7.x86_64 ipa-client-4.8.7-13.module_el8.3.0+606+1e8766d7.x86_64 389-ds-base-1.4.3.8-6.module_el8.3.0+604+ab7bf9cc.x86_64 pki-ca-10.9.4-1.module_el8.3.0+500+458aeb54.noarch krb5-server-1.18.2-5.el8.x86_64
please let me know if any particular logs, etc you might need.
Jan 10 03:16:12 hn-dlp rsyslogd[1013]: [origin software="rsyslogd" swVersion="8.1911.0-6.el8" x-pid="1013" x-info="https://www.rsyslog.com"] rsyslogd was HUPed Jan 10 03:16:14 hn-dlp named-pkcs11[1516]: LDAP configuration for instance 'ipa' synchronized Jan 10 03:16:14 hn-dlp named-pkcs11[1516]: all zones loaded Jan 10 03:16:14 hn-dlp named-pkcs11[1516]: managed-keys-zone: Key 20326 for zone . acceptance timer complete: key now trusted Jan 10 03:16:15 hn-dlp named-pkcs11[1516]: running Jan 10 03:16:15 hn-dlp named-pkcs11[1516]: LDAP data for instance 'ipa' are being synchronized, please ignore message 'all zones loaded' Jan 10 03:16:21 hn-dlp named-pkcs11[1516]: forward zone 'int.example.local': loaded Jan 10 03:16:21 hn-dlp named-pkcs11[1516]: forward zone 'srv.example.local': loaded Jan 10 03:16:21 hn-dlp named-pkcs11[1516]: zone 177.19.172.in-addr.arpa/IN: loaded serial 1610244981 Jan 10 03:16:21 hn-dlp named-pkcs11[1516]: zone 177.19.172.in-addr.arpa/IN: sending notifies (serial 1610244981) Jan 10 03:16:21 hn-dlp named-pkcs11[1516]: zone 187.19.172.in-addr.arpa/IN: loaded serial 1610244981 Jan 10 03:16:21 hn-dlp named-pkcs11[1516]: zone 195.19.172.in-addr.arpa/IN: loaded serial 1610244981 Jan 10 03:16:21 hn-dlp named-pkcs11[1516]: zone 187.19.172.in-addr.arpa/IN: sending notifies (serial 1610244981) Jan 10 03:16:21 hn-dlp named-pkcs11[1516]: zone 195.19.172.in-addr.arpa/IN: sending notifies (serial 1610244981) Jan 10 03:16:21 hn-dlp named-pkcs11[1516]: zone 197.19.172.in-addr.arpa/IN: loaded serial 1610244981 Jan 10 03:16:21 hn-dlp named-pkcs11[1516]: zone ipa.example.local/IN: loaded serial 1610244980 Jan 10 03:16:21 hn-dlp named-pkcs11[1516]: zone 197.19.172.in-addr.arpa/IN: sending notifies (serial 1610244981) Jan 10 03:16:21 hn-dlp named-pkcs11[1516]: 5 master zones from LDAP instance 'ipa' loaded (5 zones defined, 0 inactive, 0 failed to load) Jan 10 03:16:21 hn-dlp named-pkcs11[1516]: zone ipa.example.local/IN: sending notifies (serial 1610244980) Jan 10 03:16:26 hn-dlp named-pkcs11[1516]: zone 177.19.172.in-addr.arpa/IN: sending notifies (serial 1610244981) Jan 10 03:16:26 hn-dlp named-pkcs11[1516]: zone 187.19.172.in-addr.arpa/IN: sending notifies (serial 1610244981) Jan 10 03:16:26 hn-dlp named-pkcs11[1516]: zone 195.19.172.in-addr.arpa/IN: sending notifies (serial 1610244981) Jan 10 03:16:26 hn-dlp named-pkcs11[1516]: zone 197.19.172.in-addr.arpa/IN: sending notifies (serial 1610244981) Jan 10 03:16:26 hn-dlp named-pkcs11[1516]: zone ipa.example.local/IN: sending notifies (serial 1610244980) Jan 10 03:16:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:16:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 453. Jan 10 03:16:49 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:16:49 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:16:54 hn-dlp platform-python[12651]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:16:54 hn-dlp platform-python[12651]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:16:54 hn-dlp platform-python[12651]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:16:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12651]: new replica keys in LDAP: set() Jan 10 03:16:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12651]: obsolete replica keys in local HSM: set() Jan 10 03:16:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12651]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 03:16:55 hn-dlp ipa-ods-exporter[12651]: Traceback (most recent call last): Jan 10 03:16:55 hn-dlp ipa-ods-exporter[12651]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:16:55 hn-dlp ipa-ods-exporter[12651]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:16:55 hn-dlp ipa-ods-exporter[12651]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:16:55 hn-dlp ipa-ods-exporter[12651]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:16:55 hn-dlp ipa-ods-exporter[12651]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:16:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:16:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:17:10 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 03:17:10 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:17:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:17:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 454. Jan 10 03:17:55 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:17:55 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:17:59 hn-dlp platform-python[12661]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:17:59 hn-dlp platform-python[12661]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:17:59 hn-dlp platform-python[12661]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:17:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12661]: new replica keys in LDAP: set() Jan 10 03:17:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12661]: obsolete replica keys in local HSM: set() Jan 10 03:17:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12661]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 03:17:59 hn-dlp ipa-ods-exporter[12661]: Traceback (most recent call last): Jan 10 03:17:59 hn-dlp ipa-ods-exporter[12661]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:17:59 hn-dlp ipa-ods-exporter[12661]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:17:59 hn-dlp ipa-ods-exporter[12661]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:17:59 hn-dlp ipa-ods-exporter[12661]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:17:59 hn-dlp ipa-ods-exporter[12661]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:18:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:18:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:18:11 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:19:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:19:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 455. Jan 10 03:19:00 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:19:00 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:19:02 hn-dlp platform-python[12675]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:19:02 hn-dlp platform-python[12675]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:19:02 hn-dlp platform-python[12675]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:19:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12675]: new replica keys in LDAP: set() Jan 10 03:19:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12675]: obsolete replica keys in local HSM: set() Jan 10 03:19:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12675]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 03:19:03 hn-dlp ipa-ods-exporter[12675]: Traceback (most recent call last): Jan 10 03:19:03 hn-dlp ipa-ods-exporter[12675]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:19:03 hn-dlp ipa-ods-exporter[12675]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:19:03 hn-dlp ipa-ods-exporter[12675]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:19:03 hn-dlp ipa-ods-exporter[12675]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:19:03 hn-dlp ipa-ods-exporter[12675]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:19:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:19:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:19:11 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:19:11 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:20:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:20:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 456. Jan 10 03:20:03 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:20:03 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:20:06 hn-dlp platform-python[12687]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:20:06 hn-dlp platform-python[12687]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:20:06 hn-dlp platform-python[12687]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:20:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12687]: new replica keys in LDAP: set() Jan 10 03:20:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12687]: obsolete replica keys in local HSM: set() Jan 10 03:20:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12687]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 03:20:06 hn-dlp ipa-ods-exporter[12687]: Traceback (most recent call last): Jan 10 03:20:06 hn-dlp ipa-ods-exporter[12687]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:20:06 hn-dlp ipa-ods-exporter[12687]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:20:06 hn-dlp ipa-ods-exporter[12687]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:20:06 hn-dlp ipa-ods-exporter[12687]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:20:06 hn-dlp ipa-ods-exporter[12687]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:20:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:20:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:20:11 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:21:07 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:21:07 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 457. Jan 10 03:21:07 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:21:07 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:21:09 hn-dlp platform-python[12696]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:21:09 hn-dlp platform-python[12696]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:21:09 hn-dlp platform-python[12696]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:21:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12696]: new replica keys in LDAP: set() Jan 10 03:21:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12696]: obsolete replica keys in local HSM: set() Jan 10 03:21:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12696]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 03:21:09 hn-dlp ipa-ods-exporter[12696]: Traceback (most recent call last): Jan 10 03:21:09 hn-dlp ipa-ods-exporter[12696]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:21:09 hn-dlp ipa-ods-exporter[12696]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:21:09 hn-dlp ipa-ods-exporter[12696]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:21:09 hn-dlp ipa-ods-exporter[12696]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:21:09 hn-dlp ipa-ods-exporter[12696]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:21:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:21:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:21:11 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:21:11 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:22:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:22:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 458. Jan 10 03:22:10 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:22:10 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:22:11 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:22:12 hn-dlp platform-python[12704]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:22:12 hn-dlp platform-python[12704]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:22:12 hn-dlp platform-python[12704]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:22:13 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12704]: new replica keys in LDAP: set() Jan 10 03:22:13 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12704]: obsolete replica keys in local HSM: set() Jan 10 03:22:13 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12704]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:22:13 hn-dlp ipa-ods-exporter[12704]: Traceback (most recent call last): Jan 10 03:22:13 hn-dlp ipa-ods-exporter[12704]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:22:13 hn-dlp ipa-ods-exporter[12704]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:22:13 hn-dlp ipa-ods-exporter[12704]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:22:13 hn-dlp ipa-ods-exporter[12704]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:22:13 hn-dlp ipa-ods-exporter[12704]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:22:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:22:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:23:11 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:23:11 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:23:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:23:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 459. Jan 10 03:23:13 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:23:13 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:23:15 hn-dlp platform-python[12715]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:23:15 hn-dlp platform-python[12715]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:23:15 hn-dlp platform-python[12715]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:23:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12715]: new replica keys in LDAP: set() Jan 10 03:23:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12715]: obsolete replica keys in local HSM: set() Jan 10 03:23:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12715]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 03:23:16 hn-dlp ipa-ods-exporter[12715]: Traceback (most recent call last): Jan 10 03:23:16 hn-dlp ipa-ods-exporter[12715]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:23:16 hn-dlp ipa-ods-exporter[12715]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:23:16 hn-dlp ipa-ods-exporter[12715]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:23:16 hn-dlp ipa-ods-exporter[12715]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:23:16 hn-dlp ipa-ods-exporter[12715]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:23:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:23:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:24:11 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:24:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:24:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 460. Jan 10 03:24:16 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:24:16 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:24:19 hn-dlp platform-python[12724]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:24:19 hn-dlp platform-python[12724]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:24:19 hn-dlp platform-python[12724]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:24:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12724]: new replica keys in LDAP: set() Jan 10 03:24:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12724]: obsolete replica keys in local HSM: set() Jan 10 03:24:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12724]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:24:19 hn-dlp ipa-ods-exporter[12724]: Traceback (most recent call last): Jan 10 03:24:19 hn-dlp ipa-ods-exporter[12724]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:24:19 hn-dlp ipa-ods-exporter[12724]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:24:19 hn-dlp ipa-ods-exporter[12724]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:24:19 hn-dlp ipa-ods-exporter[12724]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:24:19 hn-dlp ipa-ods-exporter[12724]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:24:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:24:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:25:11 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:25:11 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:25:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:25:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 461. Jan 10 03:25:19 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:25:19 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:25:22 hn-dlp platform-python[12734]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:25:22 hn-dlp platform-python[12734]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:25:22 hn-dlp platform-python[12734]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:25:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12734]: new replica keys in LDAP: set() Jan 10 03:25:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12734]: obsolete replica keys in local HSM: set() Jan 10 03:25:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12734]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:25:22 hn-dlp ipa-ods-exporter[12734]: Traceback (most recent call last): Jan 10 03:25:22 hn-dlp ipa-ods-exporter[12734]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:25:22 hn-dlp ipa-ods-exporter[12734]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:25:22 hn-dlp ipa-ods-exporter[12734]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:25:22 hn-dlp ipa-ods-exporter[12734]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:25:22 hn-dlp ipa-ods-exporter[12734]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:25:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:25:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:26:11 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:26:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:26:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 462. Jan 10 03:26:23 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:26:23 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:26:25 hn-dlp platform-python[12744]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:26:25 hn-dlp platform-python[12744]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:26:25 hn-dlp platform-python[12744]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:26:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12744]: new replica keys in LDAP: set() Jan 10 03:26:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12744]: obsolete replica keys in local HSM: set() Jan 10 03:26:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12744]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 03:26:25 hn-dlp ipa-ods-exporter[12744]: Traceback (most recent call last): Jan 10 03:26:25 hn-dlp ipa-ods-exporter[12744]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:26:25 hn-dlp ipa-ods-exporter[12744]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:26:25 hn-dlp ipa-ods-exporter[12744]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:26:25 hn-dlp ipa-ods-exporter[12744]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:26:25 hn-dlp ipa-ods-exporter[12744]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:26:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:26:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:27:12 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 03:27:12 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:27:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:27:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 463. Jan 10 03:27:26 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:27:26 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:27:29 hn-dlp platform-python[12752]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:27:29 hn-dlp platform-python[12752]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:27:29 hn-dlp platform-python[12752]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:27:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12752]: new replica keys in LDAP: set() Jan 10 03:27:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12752]: obsolete replica keys in local HSM: set() Jan 10 03:27:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12752]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:27:29 hn-dlp ipa-ods-exporter[12752]: Traceback (most recent call last): Jan 10 03:27:29 hn-dlp ipa-ods-exporter[12752]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:27:29 hn-dlp ipa-ods-exporter[12752]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:27:29 hn-dlp ipa-ods-exporter[12752]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:27:29 hn-dlp ipa-ods-exporter[12752]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:27:29 hn-dlp ipa-ods-exporter[12752]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:27:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:27:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:28:11 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:28:19 hn-dlp systemd[1]: Starting dnf makecache... Jan 10 03:28:22 hn-dlp dnf[12764]: Updating Subscription Management repositories. Jan 10 03:28:24 hn-dlp dnf[12764]: CentOS Linux 8 - AppStream 43 kB/s | 4.3 kB 00:00 Jan 10 03:28:24 hn-dlp dnf[12764]: CentOS Linux 8 - BaseOS 80 kB/s | 3.9 kB 00:00 Jan 10 03:28:25 hn-dlp dnf[12764]: CentOS Linux 8 - Extras 25 kB/s | 1.5 kB 00:00 Jan 10 03:28:25 hn-dlp dnf[12764]: Tecin Centos 8 puppetCrlUpdater 19 kB/s | 3.4 kB 00:00 Jan 10 03:28:25 hn-dlp dnf[12764]: Rspamd8 19 kB/s | 3.5 kB 00:00 Jan 10 03:28:25 hn-dlp dnf[12764]: Puppet8 19 kB/s | 3.5 kB 00:00 Jan 10 03:28:26 hn-dlp dnf[12764]: CentOS 8 BaseOS 19 kB/s | 3.8 kB 00:00 Jan 10 03:28:26 hn-dlp dnf[12764]: Client8 21 kB/s | 3.7 kB 00:00 Jan 10 03:28:26 hn-dlp dnf[12764]: Tecin Centos 8 puppetMasterCrlUpdater 20 kB/s | 3.4 kB 00:00 Jan 10 03:28:26 hn-dlp dnf[12764]: CentOS 8 Extras 20 kB/s | 3.5 kB 00:00 Jan 10 03:28:26 hn-dlp dnf[12764]: CentOS 8 AppStream 24 kB/s | 4.1 kB 00:00 Jan 10 03:28:27 hn-dlp dnf[12764]: EPEL8 23 kB/s | 4.3 kB 00:00 Jan 10 03:28:27 hn-dlp dnf[12764]: Client8 14 kB/s | 3.5 kB 00:00 Jan 10 03:28:28 hn-dlp dnf[12764]: CentOS 8 PowerTools 19 kB/s | 4.1 kB 00:00 Jan 10 03:28:28 hn-dlp dnf[12764]: CentOS 8 CentOSPlus 17 kB/s | 3.5 kB 00:00 Jan 10 03:28:28 hn-dlp dnf[12764]: Client8-non-supported 16 kB/s | 3.4 kB 00:00 Jan 10 03:28:28 hn-dlp dnf[12764]: Tecin Centos 8 certmongerPuppetSelinuxPolicy 16 kB/s | 3.4 kB 00:00 Jan 10 03:28:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:28:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 464. Jan 10 03:28:30 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:28:30 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:28:30 hn-dlp dnf[12764]: Metadata cache created. Jan 10 03:28:30 hn-dlp systemd[1]: dnf-makecache.service: Succeeded. Jan 10 03:28:30 hn-dlp systemd[1]: Started dnf makecache. Jan 10 03:28:35 hn-dlp platform-python[12788]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:28:35 hn-dlp platform-python[12788]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:28:35 hn-dlp platform-python[12788]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:28:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12788]: new replica keys in LDAP: set() Jan 10 03:28:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12788]: obsolete replica keys in local HSM: set() Jan 10 03:28:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12788]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 03:28:35 hn-dlp ipa-ods-exporter[12788]: Traceback (most recent call last): Jan 10 03:28:35 hn-dlp ipa-ods-exporter[12788]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:28:35 hn-dlp ipa-ods-exporter[12788]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:28:35 hn-dlp ipa-ods-exporter[12788]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:28:35 hn-dlp ipa-ods-exporter[12788]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:28:35 hn-dlp ipa-ods-exporter[12788]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:28:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:28:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:29:12 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:29:12 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:29:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:29:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 465. Jan 10 03:29:35 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:29:35 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:29:35 hn-dlp rsyslogd[1013]: imjournal: journal files changed, reloading... [v8.1911.0-6.el8 try https://www.rsyslog.com/e/0 ] Jan 10 03:29:38 hn-dlp platform-python[12798]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:29:38 hn-dlp platform-python[12798]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:29:38 hn-dlp platform-python[12798]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:29:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12798]: new replica keys in LDAP: set() Jan 10 03:29:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12798]: obsolete replica keys in local HSM: set() Jan 10 03:29:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[12798]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 03:29:38 hn-dlp ipa-ods-exporter[12798]: Traceback (most recent call last): Jan 10 03:29:38 hn-dlp ipa-ods-exporter[12798]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:29:38 hn-dlp ipa-ods-exporter[12798]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:29:38 hn-dlp ipa-ods-exporter[12798]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:29:38 hn-dlp ipa-ods-exporter[12798]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:29:38 hn-dlp ipa-ods-exporter[12798]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:29:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:29:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:30:11 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:30:29 hn-dlp systemd[1]: Created slice User Slice of UID 2002. Jan 10 03:30:29 hn-dlp systemd[1]: Started /run/user/2002 mount wrapper. Jan 10 03:30:29 hn-dlp systemd[1]: Starting User Manager for UID 2002... Jan 10 03:30:29 hn-dlp systemd-logind[736]: New session 36 of user svcforeman. Jan 10 03:30:29 hn-dlp systemd[1]: Started Session 36 of user svcforeman. Jan 10 03:30:29 hn-dlp systemd[12813]: Started Mark boot as successful after the user session has run 2 minutes. Jan 10 03:30:29 hn-dlp systemd[12813]: Reached target Timers. Jan 10 03:30:29 hn-dlp systemd[12813]: Starting D-Bus User Message Bus Socket. Jan 10 03:30:29 hn-dlp systemd[12813]: Reached target Paths. Jan 10 03:30:29 hn-dlp systemd[12813]: Listening on D-Bus User Message Bus Socket. Jan 10 03:30:29 hn-dlp systemd[12813]: Reached target Sockets. Jan 10 03:30:29 hn-dlp systemd[12813]: Reached target Basic System. Jan 10 03:30:29 hn-dlp systemd[12813]: Reached target Default. Jan 10 03:30:29 hn-dlp systemd[12813]: Startup finished in 114ms. Jan 10 03:30:29 hn-dlp systemd[1]: Started User Manager for UID 2002. Jan 10 03:30:32 hn-dlp platform-python[12975]: ansible-setup Invoked with gather_timeout=10 gather_subset=['all'] filter=* fact_path=/etc/ansible/facts.d Jan 10 03:30:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:30:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 466. Jan 10 03:30:39 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:30:39 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:30:42 hn-dlp platform-python[13080]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:30:42 hn-dlp platform-python[13080]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:30:42 hn-dlp platform-python[13080]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:30:42 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13080]: new replica keys in LDAP: set() Jan 10 03:30:42 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13080]: obsolete replica keys in local HSM: set() Jan 10 03:30:42 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13080]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 03:30:42 hn-dlp ipa-ods-exporter[13080]: Traceback (most recent call last): Jan 10 03:30:42 hn-dlp ipa-ods-exporter[13080]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:30:42 hn-dlp ipa-ods-exporter[13080]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:30:42 hn-dlp ipa-ods-exporter[13080]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:30:42 hn-dlp ipa-ods-exporter[13080]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:30:42 hn-dlp ipa-ods-exporter[13080]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:30:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:30:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:31:12 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:31:12 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:31:39 hn-dlp systemd[1]: session-36.scope: Succeeded. Jan 10 03:31:39 hn-dlp systemd-logind[736]: Session 36 logged out. Waiting for processes to exit. Jan 10 03:31:39 hn-dlp systemd-logind[736]: Removed session 36. Jan 10 03:31:39 hn-dlp systemd[1]: Stopping User Manager for UID 2002... Jan 10 03:31:39 hn-dlp systemd[12813]: Stopped target Default. Jan 10 03:31:39 hn-dlp systemd[12813]: Stopped target Basic System. Jan 10 03:31:39 hn-dlp systemd[12813]: Stopped target Sockets. Jan 10 03:31:39 hn-dlp systemd[12813]: dbus.socket: Succeeded. Jan 10 03:31:39 hn-dlp systemd[12813]: Closed D-Bus User Message Bus Socket. Jan 10 03:31:39 hn-dlp systemd[12813]: Stopped target Timers. Jan 10 03:31:39 hn-dlp systemd[12813]: grub-boot-success.timer: Succeeded. Jan 10 03:31:39 hn-dlp systemd[12813]: Stopped Mark boot as successful after the user session has run 2 minutes. Jan 10 03:31:39 hn-dlp systemd[12813]: Stopped target Paths. Jan 10 03:31:39 hn-dlp systemd[12813]: Reached target Shutdown. Jan 10 03:31:39 hn-dlp systemd[12813]: Starting Exit the Session... Jan 10 03:31:39 hn-dlp systemd[1]: user@2002.service: Succeeded. Jan 10 03:31:39 hn-dlp systemd[1]: Stopped User Manager for UID 2002. Jan 10 03:31:39 hn-dlp systemd[1]: Stopping /run/user/2002 mount wrapper... Jan 10 03:31:39 hn-dlp systemd[1]: Removed slice User Slice of UID 2002. Jan 10 03:31:39 hn-dlp systemd[1]: run-user-2002.mount: Succeeded. Jan 10 03:31:39 hn-dlp systemd[1]: user-runtime-dir@2002.service: Succeeded. Jan 10 03:31:39 hn-dlp systemd[1]: Stopped /run/user/2002 mount wrapper. Jan 10 03:31:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:31:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 467. Jan 10 03:31:42 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:31:42 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:31:46 hn-dlp platform-python[13105]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:31:46 hn-dlp platform-python[13105]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:31:46 hn-dlp platform-python[13105]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:31:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13105]: new replica keys in LDAP: set() Jan 10 03:31:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13105]: obsolete replica keys in local HSM: set() Jan 10 03:31:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13105]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:31:46 hn-dlp ipa-ods-exporter[13105]: Traceback (most recent call last): Jan 10 03:31:46 hn-dlp ipa-ods-exporter[13105]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:31:46 hn-dlp ipa-ods-exporter[13105]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:31:46 hn-dlp ipa-ods-exporter[13105]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:31:46 hn-dlp ipa-ods-exporter[13105]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:31:46 hn-dlp ipa-ods-exporter[13105]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:31:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:31:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:32:11 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:32:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:32:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 468. Jan 10 03:32:46 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:32:46 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:32:49 hn-dlp platform-python[13113]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:32:49 hn-dlp platform-python[13113]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:32:49 hn-dlp platform-python[13113]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:32:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13113]: new replica keys in LDAP: set() Jan 10 03:32:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13113]: obsolete replica keys in local HSM: set() Jan 10 03:32:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13113]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 03:32:49 hn-dlp ipa-ods-exporter[13113]: Traceback (most recent call last): Jan 10 03:32:49 hn-dlp ipa-ods-exporter[13113]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:32:49 hn-dlp ipa-ods-exporter[13113]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:32:49 hn-dlp ipa-ods-exporter[13113]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:32:49 hn-dlp ipa-ods-exporter[13113]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:32:49 hn-dlp ipa-ods-exporter[13113]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:32:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:32:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:33:12 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:33:12 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:33:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:33:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 469. Jan 10 03:33:50 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:33:50 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:33:52 hn-dlp platform-python[13122]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:33:52 hn-dlp platform-python[13122]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:33:52 hn-dlp platform-python[13122]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:33:52 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13122]: new replica keys in LDAP: set() Jan 10 03:33:52 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13122]: obsolete replica keys in local HSM: set() Jan 10 03:33:52 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13122]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:33:53 hn-dlp ipa-ods-exporter[13122]: Traceback (most recent call last): Jan 10 03:33:53 hn-dlp ipa-ods-exporter[13122]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:33:53 hn-dlp ipa-ods-exporter[13122]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:33:53 hn-dlp ipa-ods-exporter[13122]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:33:53 hn-dlp ipa-ods-exporter[13122]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:33:53 hn-dlp ipa-ods-exporter[13122]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:33:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:33:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:34:11 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:34:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:34:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 470. Jan 10 03:34:53 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:34:53 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:34:55 hn-dlp platform-python[13132]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:34:55 hn-dlp platform-python[13132]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:34:55 hn-dlp platform-python[13132]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:34:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13132]: new replica keys in LDAP: set() Jan 10 03:34:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13132]: obsolete replica keys in local HSM: set() Jan 10 03:34:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13132]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 03:34:56 hn-dlp ipa-ods-exporter[13132]: Traceback (most recent call last): Jan 10 03:34:56 hn-dlp ipa-ods-exporter[13132]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:34:56 hn-dlp ipa-ods-exporter[13132]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:34:56 hn-dlp ipa-ods-exporter[13132]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:34:56 hn-dlp ipa-ods-exporter[13132]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:34:56 hn-dlp ipa-ods-exporter[13132]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:34:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:34:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:35:12 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:35:12 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:35:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:35:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 471. Jan 10 03:35:56 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:35:56 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:35:58 hn-dlp platform-python[13141]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:35:58 hn-dlp platform-python[13141]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:35:58 hn-dlp platform-python[13141]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:35:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13141]: new replica keys in LDAP: set() Jan 10 03:35:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13141]: obsolete replica keys in local HSM: set() Jan 10 03:35:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13141]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:35:59 hn-dlp ipa-ods-exporter[13141]: Traceback (most recent call last): Jan 10 03:35:59 hn-dlp ipa-ods-exporter[13141]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:35:59 hn-dlp ipa-ods-exporter[13141]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:35:59 hn-dlp ipa-ods-exporter[13141]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:35:59 hn-dlp ipa-ods-exporter[13141]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:35:59 hn-dlp ipa-ods-exporter[13141]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:35:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:35:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:36:12 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:36:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:36:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 472. Jan 10 03:36:59 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:36:59 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:37:02 hn-dlp platform-python[13151]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:37:02 hn-dlp platform-python[13151]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:37:02 hn-dlp platform-python[13151]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:37:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13151]: new replica keys in LDAP: set() Jan 10 03:37:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13151]: obsolete replica keys in local HSM: set() Jan 10 03:37:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13151]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:37:02 hn-dlp ipa-ods-exporter[13151]: Traceback (most recent call last): Jan 10 03:37:02 hn-dlp ipa-ods-exporter[13151]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:37:02 hn-dlp ipa-ods-exporter[13151]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:37:02 hn-dlp ipa-ods-exporter[13151]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:37:02 hn-dlp ipa-ods-exporter[13151]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:37:02 hn-dlp ipa-ods-exporter[13151]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:37:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:37:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:37:13 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 03:37:13 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:38:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:38:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 473. Jan 10 03:38:03 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:38:03 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:38:05 hn-dlp platform-python[13160]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:38:05 hn-dlp platform-python[13160]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:38:05 hn-dlp platform-python[13160]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:38:05 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13160]: new replica keys in LDAP: set() Jan 10 03:38:05 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13160]: obsolete replica keys in local HSM: set() Jan 10 03:38:05 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13160]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:38:05 hn-dlp ipa-ods-exporter[13160]: Traceback (most recent call last): Jan 10 03:38:05 hn-dlp ipa-ods-exporter[13160]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:38:05 hn-dlp ipa-ods-exporter[13160]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:38:05 hn-dlp ipa-ods-exporter[13160]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:38:05 hn-dlp ipa-ods-exporter[13160]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:38:05 hn-dlp ipa-ods-exporter[13160]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:38:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:38:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:38:12 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:38:33 hn-dlp named-pkcs11[1516]: client @0x7fb2f4126fe0 172.19.197.2#45778: received notify for zone 'ipa.example.local' Jan 10 03:38:33 hn-dlp named-pkcs11[1516]: client @0x7fb2f4043e40 172.19.197.2#45778: received notify for zone '197.19.172.in-addr.arpa' Jan 10 03:38:33 hn-dlp named-pkcs11[1516]: client @0x7fb2f4043e40 172.19.197.2#45778: received notify for zone '177.19.172.in-addr.arpa' Jan 10 03:38:33 hn-dlp named-pkcs11[1516]: client @0x7fb2f40fac70 172.19.197.2#45778: received notify for zone '195.19.172.in-addr.arpa' Jan 10 03:38:33 hn-dlp named-pkcs11[1516]: client @0x7fb2f4126fe0 172.19.197.2#45778: received notify for zone '187.19.172.in-addr.arpa' Jan 10 03:38:38 hn-dlp named-pkcs11[1516]: client @0x7fb2f4126fe0 172.19.197.2#45778: received notify for zone '177.19.172.in-addr.arpa' Jan 10 03:38:38 hn-dlp named-pkcs11[1516]: client @0x7fb2f4126fe0 172.19.197.2#45778: received notify for zone '197.19.172.in-addr.arpa' Jan 10 03:38:38 hn-dlp named-pkcs11[1516]: client @0x7fb2f4126fe0 172.19.197.2#45778: received notify for zone 'ipa.example.local' Jan 10 03:38:38 hn-dlp named-pkcs11[1516]: client @0x7fb2f40fac70 172.19.197.2#45778: received notify for zone '195.19.172.in-addr.arpa' Jan 10 03:38:38 hn-dlp named-pkcs11[1516]: client @0x7fb2f4043e40 172.19.197.2#45778: received notify for zone '187.19.172.in-addr.arpa' Jan 10 03:39:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:39:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 474. Jan 10 03:39:06 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:39:06 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:39:09 hn-dlp platform-python[13169]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:39:09 hn-dlp platform-python[13169]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:39:09 hn-dlp platform-python[13169]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:39:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13169]: new replica keys in LDAP: set() Jan 10 03:39:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13169]: obsolete replica keys in local HSM: set() Jan 10 03:39:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13169]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 03:39:09 hn-dlp ipa-ods-exporter[13169]: Traceback (most recent call last): Jan 10 03:39:09 hn-dlp ipa-ods-exporter[13169]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:39:09 hn-dlp ipa-ods-exporter[13169]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:39:09 hn-dlp ipa-ods-exporter[13169]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:39:09 hn-dlp ipa-ods-exporter[13169]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:39:09 hn-dlp ipa-ods-exporter[13169]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:39:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:39:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:39:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:39:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:40:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:40:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 475. Jan 10 03:40:09 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:40:09 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:40:12 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:40:12 hn-dlp platform-python[13181]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:40:12 hn-dlp platform-python[13181]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:40:12 hn-dlp platform-python[13181]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:40:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13181]: new replica keys in LDAP: set() Jan 10 03:40:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13181]: obsolete replica keys in local HSM: set() Jan 10 03:40:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13181]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 03:40:12 hn-dlp ipa-ods-exporter[13181]: Traceback (most recent call last): Jan 10 03:40:12 hn-dlp ipa-ods-exporter[13181]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:40:12 hn-dlp ipa-ods-exporter[13181]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:40:12 hn-dlp ipa-ods-exporter[13181]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:40:12 hn-dlp ipa-ods-exporter[13181]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:40:12 hn-dlp ipa-ods-exporter[13181]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:40:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:40:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:41:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:41:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 476. Jan 10 03:41:13 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:41:13 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:41:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:41:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:41:15 hn-dlp platform-python[13190]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:41:15 hn-dlp platform-python[13190]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:41:15 hn-dlp platform-python[13190]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:41:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13190]: new replica keys in LDAP: set() Jan 10 03:41:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13190]: obsolete replica keys in local HSM: set() Jan 10 03:41:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13190]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 03:41:16 hn-dlp ipa-ods-exporter[13190]: Traceback (most recent call last): Jan 10 03:41:16 hn-dlp ipa-ods-exporter[13190]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:41:16 hn-dlp ipa-ods-exporter[13190]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:41:16 hn-dlp ipa-ods-exporter[13190]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:41:16 hn-dlp ipa-ods-exporter[13190]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:41:16 hn-dlp ipa-ods-exporter[13190]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:41:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:41:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:42:12 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:42:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:42:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 477. Jan 10 03:42:16 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:42:16 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:42:19 hn-dlp platform-python[13200]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:42:19 hn-dlp platform-python[13200]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:42:19 hn-dlp platform-python[13200]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:42:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13200]: new replica keys in LDAP: set() Jan 10 03:42:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13200]: obsolete replica keys in local HSM: set() Jan 10 03:42:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13200]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:42:19 hn-dlp ipa-ods-exporter[13200]: Traceback (most recent call last): Jan 10 03:42:19 hn-dlp ipa-ods-exporter[13200]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:42:19 hn-dlp ipa-ods-exporter[13200]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:42:19 hn-dlp ipa-ods-exporter[13200]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:42:19 hn-dlp ipa-ods-exporter[13200]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:42:19 hn-dlp ipa-ods-exporter[13200]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:42:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:42:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:43:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:43:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:43:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:43:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 478. Jan 10 03:43:19 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:43:19 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:43:22 hn-dlp platform-python[13209]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:43:22 hn-dlp platform-python[13209]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:43:22 hn-dlp platform-python[13209]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:43:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13209]: new replica keys in LDAP: set() Jan 10 03:43:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13209]: obsolete replica keys in local HSM: set() Jan 10 03:43:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13209]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:43:22 hn-dlp ipa-ods-exporter[13209]: Traceback (most recent call last): Jan 10 03:43:22 hn-dlp ipa-ods-exporter[13209]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:43:22 hn-dlp ipa-ods-exporter[13209]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:43:22 hn-dlp ipa-ods-exporter[13209]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:43:22 hn-dlp ipa-ods-exporter[13209]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:43:22 hn-dlp ipa-ods-exporter[13209]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:43:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:43:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:44:12 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:44:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:44:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 479. Jan 10 03:44:23 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:44:23 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:44:25 hn-dlp platform-python[13217]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:44:25 hn-dlp platform-python[13217]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:44:25 hn-dlp platform-python[13217]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:44:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13217]: new replica keys in LDAP: set() Jan 10 03:44:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13217]: obsolete replica keys in local HSM: set() Jan 10 03:44:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13217]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:44:25 hn-dlp ipa-ods-exporter[13217]: Traceback (most recent call last): Jan 10 03:44:25 hn-dlp ipa-ods-exporter[13217]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:44:25 hn-dlp ipa-ods-exporter[13217]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:44:25 hn-dlp ipa-ods-exporter[13217]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:44:25 hn-dlp ipa-ods-exporter[13217]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:44:25 hn-dlp ipa-ods-exporter[13217]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:44:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:44:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:45:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:45:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:45:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:45:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 480. Jan 10 03:45:26 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:45:26 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:45:28 hn-dlp platform-python[13228]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:45:28 hn-dlp platform-python[13228]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:45:28 hn-dlp platform-python[13228]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:45:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13228]: new replica keys in LDAP: set() Jan 10 03:45:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13228]: obsolete replica keys in local HSM: set() Jan 10 03:45:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13228]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:45:29 hn-dlp ipa-ods-exporter[13228]: Traceback (most recent call last): Jan 10 03:45:29 hn-dlp ipa-ods-exporter[13228]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:45:29 hn-dlp ipa-ods-exporter[13228]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:45:29 hn-dlp ipa-ods-exporter[13228]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:45:29 hn-dlp ipa-ods-exporter[13228]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:45:29 hn-dlp ipa-ods-exporter[13228]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:45:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:45:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:46:12 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:46:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:46:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 481. Jan 10 03:46:29 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:46:29 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:46:31 hn-dlp platform-python[13237]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:46:31 hn-dlp platform-python[13237]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:46:31 hn-dlp platform-python[13237]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:46:32 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13237]: new replica keys in LDAP: set() Jan 10 03:46:32 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13237]: obsolete replica keys in local HSM: set() Jan 10 03:46:32 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13237]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 03:46:32 hn-dlp ipa-ods-exporter[13237]: Traceback (most recent call last): Jan 10 03:46:32 hn-dlp ipa-ods-exporter[13237]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:46:32 hn-dlp ipa-ods-exporter[13237]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:46:32 hn-dlp ipa-ods-exporter[13237]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:46:32 hn-dlp ipa-ods-exporter[13237]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:46:32 hn-dlp ipa-ods-exporter[13237]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:46:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:46:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:47:13 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 03:47:13 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:47:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:47:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 482. Jan 10 03:47:32 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:47:32 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:47:35 hn-dlp platform-python[13246]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:47:35 hn-dlp platform-python[13246]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:47:35 hn-dlp platform-python[13246]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:47:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13246]: new replica keys in LDAP: set() Jan 10 03:47:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13246]: obsolete replica keys in local HSM: set() Jan 10 03:47:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13246]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 03:47:35 hn-dlp ipa-ods-exporter[13246]: Traceback (most recent call last): Jan 10 03:47:35 hn-dlp ipa-ods-exporter[13246]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:47:35 hn-dlp ipa-ods-exporter[13246]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:47:35 hn-dlp ipa-ods-exporter[13246]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:47:35 hn-dlp ipa-ods-exporter[13246]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:47:35 hn-dlp ipa-ods-exporter[13246]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:47:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:47:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:48:12 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:48:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:48:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 483. Jan 10 03:48:35 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:48:35 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:48:38 hn-dlp platform-python[13256]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:48:38 hn-dlp platform-python[13256]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:48:38 hn-dlp platform-python[13256]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:48:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13256]: new replica keys in LDAP: set() Jan 10 03:48:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13256]: obsolete replica keys in local HSM: set() Jan 10 03:48:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13256]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 03:48:38 hn-dlp ipa-ods-exporter[13256]: Traceback (most recent call last): Jan 10 03:48:38 hn-dlp ipa-ods-exporter[13256]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:48:38 hn-dlp ipa-ods-exporter[13256]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:48:38 hn-dlp ipa-ods-exporter[13256]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:48:38 hn-dlp ipa-ods-exporter[13256]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:48:38 hn-dlp ipa-ods-exporter[13256]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:48:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:48:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:49:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:49:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:49:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:49:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 484. Jan 10 03:49:39 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:49:39 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:49:41 hn-dlp platform-python[13266]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:49:41 hn-dlp platform-python[13266]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:49:41 hn-dlp platform-python[13266]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:49:41 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13266]: new replica keys in LDAP: set() Jan 10 03:49:41 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13266]: obsolete replica keys in local HSM: set() Jan 10 03:49:41 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13266]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 03:49:41 hn-dlp ipa-ods-exporter[13266]: Traceback (most recent call last): Jan 10 03:49:41 hn-dlp ipa-ods-exporter[13266]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:49:41 hn-dlp ipa-ods-exporter[13266]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:49:41 hn-dlp ipa-ods-exporter[13266]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:49:41 hn-dlp ipa-ods-exporter[13266]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:49:41 hn-dlp ipa-ods-exporter[13266]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:49:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:49:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:50:12 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:50:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:50:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 485. Jan 10 03:50:42 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:50:42 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:50:44 hn-dlp platform-python[13276]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:50:44 hn-dlp platform-python[13276]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:50:44 hn-dlp platform-python[13276]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:50:45 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13276]: new replica keys in LDAP: set() Jan 10 03:50:45 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13276]: obsolete replica keys in local HSM: set() Jan 10 03:50:45 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13276]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 03:50:45 hn-dlp ipa-ods-exporter[13276]: Traceback (most recent call last): Jan 10 03:50:45 hn-dlp ipa-ods-exporter[13276]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:50:45 hn-dlp ipa-ods-exporter[13276]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:50:45 hn-dlp ipa-ods-exporter[13276]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:50:45 hn-dlp ipa-ods-exporter[13276]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:50:45 hn-dlp ipa-ods-exporter[13276]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:50:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:50:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:51:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:51:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:51:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:51:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 486. Jan 10 03:51:45 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:51:45 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:51:48 hn-dlp platform-python[13287]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:51:48 hn-dlp platform-python[13287]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:51:48 hn-dlp platform-python[13287]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:51:48 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13287]: new replica keys in LDAP: set() Jan 10 03:51:48 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13287]: obsolete replica keys in local HSM: set() Jan 10 03:51:48 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13287]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:51:48 hn-dlp ipa-ods-exporter[13287]: Traceback (most recent call last): Jan 10 03:51:48 hn-dlp ipa-ods-exporter[13287]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:51:48 hn-dlp ipa-ods-exporter[13287]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:51:48 hn-dlp ipa-ods-exporter[13287]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:51:48 hn-dlp ipa-ods-exporter[13287]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:51:48 hn-dlp ipa-ods-exporter[13287]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:51:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:51:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:52:12 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:52:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:52:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 487. Jan 10 03:52:48 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:52:48 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:52:51 hn-dlp platform-python[13295]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:52:51 hn-dlp platform-python[13295]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:52:51 hn-dlp platform-python[13295]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:52:51 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13295]: new replica keys in LDAP: set() Jan 10 03:52:51 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13295]: obsolete replica keys in local HSM: set() Jan 10 03:52:51 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13295]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 03:52:51 hn-dlp ipa-ods-exporter[13295]: Traceback (most recent call last): Jan 10 03:52:51 hn-dlp ipa-ods-exporter[13295]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:52:51 hn-dlp ipa-ods-exporter[13295]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:52:51 hn-dlp ipa-ods-exporter[13295]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:52:51 hn-dlp ipa-ods-exporter[13295]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:52:51 hn-dlp ipa-ods-exporter[13295]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:52:51 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:52:51 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:53:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:53:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:53:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:53:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 488. Jan 10 03:53:52 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:53:52 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:53:54 hn-dlp platform-python[13306]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:53:54 hn-dlp platform-python[13306]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:53:54 hn-dlp platform-python[13306]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:53:54 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13306]: new replica keys in LDAP: set() Jan 10 03:53:54 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13306]: obsolete replica keys in local HSM: set() Jan 10 03:53:54 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13306]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:53:54 hn-dlp ipa-ods-exporter[13306]: Traceback (most recent call last): Jan 10 03:53:54 hn-dlp ipa-ods-exporter[13306]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:53:54 hn-dlp ipa-ods-exporter[13306]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:53:54 hn-dlp ipa-ods-exporter[13306]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:53:54 hn-dlp ipa-ods-exporter[13306]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:53:54 hn-dlp ipa-ods-exporter[13306]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:53:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:53:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:54:12 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:54:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:54:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 489. Jan 10 03:54:55 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:54:55 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:54:57 hn-dlp platform-python[13317]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:54:57 hn-dlp platform-python[13317]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:54:57 hn-dlp platform-python[13317]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:54:57 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13317]: new replica keys in LDAP: set() Jan 10 03:54:57 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13317]: obsolete replica keys in local HSM: set() Jan 10 03:54:57 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13317]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 03:54:57 hn-dlp ipa-ods-exporter[13317]: Traceback (most recent call last): Jan 10 03:54:57 hn-dlp ipa-ods-exporter[13317]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:54:57 hn-dlp ipa-ods-exporter[13317]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:54:57 hn-dlp ipa-ods-exporter[13317]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:54:57 hn-dlp ipa-ods-exporter[13317]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:54:57 hn-dlp ipa-ods-exporter[13317]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:54:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:54:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:55:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:55:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:55:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:55:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 490. Jan 10 03:55:58 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:55:58 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:56:01 hn-dlp platform-python[13327]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:56:01 hn-dlp platform-python[13327]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:56:01 hn-dlp platform-python[13327]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:56:01 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13327]: new replica keys in LDAP: set() Jan 10 03:56:01 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13327]: obsolete replica keys in local HSM: set() Jan 10 03:56:01 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13327]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 03:56:01 hn-dlp ipa-ods-exporter[13327]: Traceback (most recent call last): Jan 10 03:56:01 hn-dlp ipa-ods-exporter[13327]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:56:01 hn-dlp ipa-ods-exporter[13327]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:56:01 hn-dlp ipa-ods-exporter[13327]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:56:01 hn-dlp ipa-ods-exporter[13327]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:56:01 hn-dlp ipa-ods-exporter[13327]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:56:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:56:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:56:12 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:57:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:57:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 491. Jan 10 03:57:01 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:57:01 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:57:04 hn-dlp platform-python[13335]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:57:04 hn-dlp platform-python[13335]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:57:04 hn-dlp platform-python[13335]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:57:04 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13335]: new replica keys in LDAP: set() Jan 10 03:57:04 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13335]: obsolete replica keys in local HSM: set() Jan 10 03:57:04 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13335]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 03:57:04 hn-dlp ipa-ods-exporter[13335]: Traceback (most recent call last): Jan 10 03:57:04 hn-dlp ipa-ods-exporter[13335]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:57:04 hn-dlp ipa-ods-exporter[13335]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:57:04 hn-dlp ipa-ods-exporter[13335]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:57:04 hn-dlp ipa-ods-exporter[13335]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:57:04 hn-dlp ipa-ods-exporter[13335]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:57:04 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:57:04 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:57:13 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 03:57:13 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 03:58:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:58:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 492. Jan 10 03:58:05 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:58:05 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:58:07 hn-dlp platform-python[13344]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:58:07 hn-dlp platform-python[13344]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:58:07 hn-dlp platform-python[13344]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:58:07 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13344]: new replica keys in LDAP: set() Jan 10 03:58:07 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13344]: obsolete replica keys in local HSM: set() Jan 10 03:58:07 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13344]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:58:07 hn-dlp ipa-ods-exporter[13344]: Traceback (most recent call last): Jan 10 03:58:07 hn-dlp ipa-ods-exporter[13344]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:58:07 hn-dlp ipa-ods-exporter[13344]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:58:07 hn-dlp ipa-ods-exporter[13344]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:58:07 hn-dlp ipa-ods-exporter[13344]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:58:07 hn-dlp ipa-ods-exporter[13344]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:58:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:58:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:58:12 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 03:59:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 03:59:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 493. Jan 10 03:59:08 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 03:59:08 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 03:59:10 hn-dlp platform-python[13354]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 03:59:10 hn-dlp platform-python[13354]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 03:59:10 hn-dlp platform-python[13354]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 03:59:11 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13354]: new replica keys in LDAP: set() Jan 10 03:59:11 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13354]: obsolete replica keys in local HSM: set() Jan 10 03:59:11 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13354]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 03:59:11 hn-dlp ipa-ods-exporter[13354]: Traceback (most recent call last): Jan 10 03:59:11 hn-dlp ipa-ods-exporter[13354]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 03:59:11 hn-dlp ipa-ods-exporter[13354]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 03:59:11 hn-dlp ipa-ods-exporter[13354]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 03:59:11 hn-dlp ipa-ods-exporter[13354]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 03:59:11 hn-dlp ipa-ods-exporter[13354]: KeyError: 'popitem(): dictionary is empty' Jan 10 03:59:11 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 03:59:11 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 03:59:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 03:59:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:01 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '168.192.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 04:00:01 hn-dlp named-pkcs11[1516]: no valid DS resolving '2.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:01 hn-dlp named-pkcs11[1516]: validating 4.133.168.192.in-addr.arpa/PTR: bad cache hit (168.192.in-addr.arpa/DS) Jan 10 04:00:01 hn-dlp named-pkcs11[1516]: broken trust chain resolving '4.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:01 hn-dlp named-pkcs11[1516]: validating 3.133.168.192.in-addr.arpa/PTR: bad cache hit (168.192.in-addr.arpa/DS) Jan 10 04:00:01 hn-dlp named-pkcs11[1516]: broken trust chain resolving '3.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:02 hn-dlp named-pkcs11[1516]: validating 104.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '104.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:02 hn-dlp named-pkcs11[1516]: validating 109.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '109.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:02 hn-dlp named-pkcs11[1516]: validating 110.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '110.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:02 hn-dlp named-pkcs11[1516]: validating 113.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '113.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:02 hn-dlp named-pkcs11[1516]: validating 191.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '191.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:02 hn-dlp named-pkcs11[1516]: validating 192.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '192.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 203.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '203.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 254.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '254.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 104.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '104.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 171.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '171.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 173.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '173.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 183.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '183.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 204.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '204.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 213.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '213.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 216.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '216.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 217.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '217.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 1.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 5.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '5.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 14.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '14.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 15.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '15.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 1.171.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.171.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 2.171.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '2.171.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 100.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '100.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 103.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '103.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: validating 254.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '254.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:04 hn-dlp named-pkcs11[1516]: validating 104.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:04 hn-dlp named-pkcs11[1516]: broken trust chain resolving '104.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:04 hn-dlp named-pkcs11[1516]: validating 107.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:04 hn-dlp named-pkcs11[1516]: broken trust chain resolving '107.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:04 hn-dlp named-pkcs11[1516]: validating 254.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:04 hn-dlp named-pkcs11[1516]: broken trust chain resolving '254.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:04 hn-dlp named-pkcs11[1516]: validating 5.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:04 hn-dlp named-pkcs11[1516]: broken trust chain resolving '5.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:04 hn-dlp named-pkcs11[1516]: validating 11.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:04 hn-dlp named-pkcs11[1516]: broken trust chain resolving '11.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:04 hn-dlp named-pkcs11[1516]: validating 100.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:04 hn-dlp named-pkcs11[1516]: broken trust chain resolving '100.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:04 hn-dlp named-pkcs11[1516]: validating 254.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:00:04 hn-dlp named-pkcs11[1516]: broken trust chain resolving '254.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:00:11 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:00:11 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 494. Jan 10 04:00:11 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:00:11 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:00:12 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:00:14 hn-dlp platform-python[13363]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:00:14 hn-dlp platform-python[13363]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:00:14 hn-dlp platform-python[13363]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:00:14 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13363]: new replica keys in LDAP: set() Jan 10 04:00:14 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13363]: obsolete replica keys in local HSM: set() Jan 10 04:00:14 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13363]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:00:14 hn-dlp ipa-ods-exporter[13363]: Traceback (most recent call last): Jan 10 04:00:14 hn-dlp ipa-ods-exporter[13363]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:00:14 hn-dlp ipa-ods-exporter[13363]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:00:14 hn-dlp ipa-ods-exporter[13363]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:00:14 hn-dlp ipa-ods-exporter[13363]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:00:14 hn-dlp ipa-ods-exporter[13363]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:00:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:00:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:00:30 hn-dlp systemd[1]: Started /run/user/2002 mount wrapper. Jan 10 04:00:30 hn-dlp systemd[1]: Created slice User Slice of UID 2002. Jan 10 04:00:30 hn-dlp systemd[1]: Starting User Manager for UID 2002... Jan 10 04:00:30 hn-dlp systemd-logind[736]: New session 38 of user svcforeman. Jan 10 04:00:30 hn-dlp systemd[1]: Started Session 38 of user svcforeman. Jan 10 04:00:31 hn-dlp systemd[13379]: Starting D-Bus User Message Bus Socket. Jan 10 04:00:31 hn-dlp systemd[13379]: Reached target Paths. Jan 10 04:00:31 hn-dlp systemd[13379]: Started Mark boot as successful after the user session has run 2 minutes. Jan 10 04:00:31 hn-dlp systemd[13379]: Reached target Timers. Jan 10 04:00:31 hn-dlp systemd[13379]: Listening on D-Bus User Message Bus Socket. Jan 10 04:00:31 hn-dlp systemd[13379]: Reached target Sockets. Jan 10 04:00:31 hn-dlp systemd[13379]: Reached target Basic System. Jan 10 04:00:31 hn-dlp systemd[13379]: Reached target Default. Jan 10 04:00:31 hn-dlp systemd[13379]: Startup finished in 120ms. Jan 10 04:00:31 hn-dlp systemd[1]: Started User Manager for UID 2002. Jan 10 04:00:34 hn-dlp platform-python[13541]: ansible-setup Invoked with gather_timeout=10 gather_subset=['all'] filter=* fact_path=/etc/ansible/facts.d Jan 10 04:01:05 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.131' (uid=0 pid=669 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 04:01:05 hn-dlp dbus-daemon[13660]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 04:01:08 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 04:01:09 hn-dlp setroubleshoot[13660]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-010000.der Jan 10 04:01:09 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.931' (uid=995 pid=13660 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 04:01:09 hn-dlp dbus-daemon[13673]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 04:01:11 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 04:01:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:01:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:01:14 hn-dlp setroubleshoot[13660]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-010000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 04:01:14 hn-dlp setroubleshoot[13660]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-010000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-010000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 04:01:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:01:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 495. Jan 10 04:01:14 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:01:14 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:01:23 hn-dlp platform-python[13677]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:01:23 hn-dlp platform-python[13677]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:01:23 hn-dlp platform-python[13677]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:01:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13677]: new replica keys in LDAP: set() Jan 10 04:01:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13677]: obsolete replica keys in local HSM: set() Jan 10 04:01:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13677]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:01:23 hn-dlp ipa-ods-exporter[13677]: Traceback (most recent call last): Jan 10 04:01:23 hn-dlp ipa-ods-exporter[13677]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:01:23 hn-dlp ipa-ods-exporter[13677]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:01:23 hn-dlp ipa-ods-exporter[13677]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:01:23 hn-dlp ipa-ods-exporter[13677]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:01:23 hn-dlp ipa-ods-exporter[13677]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:01:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:01:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:01:37 hn-dlp systemd[1]: session-38.scope: Succeeded. Jan 10 04:01:37 hn-dlp systemd-logind[736]: Session 38 logged out. Waiting for processes to exit. Jan 10 04:01:37 hn-dlp systemd-logind[736]: Removed session 38. Jan 10 04:01:37 hn-dlp systemd[1]: Stopping User Manager for UID 2002... Jan 10 04:01:37 hn-dlp systemd[13379]: Stopped target Default. Jan 10 04:01:37 hn-dlp systemd[13379]: Stopped target Basic System. Jan 10 04:01:37 hn-dlp systemd[13379]: Stopped target Sockets. Jan 10 04:01:37 hn-dlp systemd[13379]: dbus.socket: Succeeded. Jan 10 04:01:37 hn-dlp systemd[13379]: Closed D-Bus User Message Bus Socket. Jan 10 04:01:37 hn-dlp systemd[13379]: Stopped target Paths. Jan 10 04:01:37 hn-dlp systemd[13379]: Stopped target Timers. Jan 10 04:01:37 hn-dlp systemd[13379]: grub-boot-success.timer: Succeeded. Jan 10 04:01:37 hn-dlp systemd[13379]: Stopped Mark boot as successful after the user session has run 2 minutes. Jan 10 04:01:37 hn-dlp systemd[13379]: Reached target Shutdown. Jan 10 04:01:37 hn-dlp systemd[13379]: Starting Exit the Session... Jan 10 04:01:37 hn-dlp systemd[1]: user@2002.service: Succeeded. Jan 10 04:01:37 hn-dlp systemd[1]: Stopped User Manager for UID 2002. Jan 10 04:01:37 hn-dlp systemd[1]: Stopping /run/user/2002 mount wrapper... Jan 10 04:01:37 hn-dlp systemd[1]: Removed slice User Slice of UID 2002. Jan 10 04:01:37 hn-dlp systemd[1]: run-user-2002.mount: Succeeded. Jan 10 04:01:37 hn-dlp systemd[1]: user-runtime-dir@2002.service: Succeeded. Jan 10 04:01:37 hn-dlp systemd[1]: Stopped /run/user/2002 mount wrapper. Jan 10 04:02:05 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.131' (uid=0 pid=669 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 04:02:05 hn-dlp dbus-daemon[13697]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 04:02:08 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 04:02:09 hn-dlp setroubleshoot[13697]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-010000.der Jan 10 04:02:09 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.938' (uid=995 pid=13697 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 04:02:09 hn-dlp dbus-daemon[13709]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 04:02:09 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 04:02:11 hn-dlp setroubleshoot[13697]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-010000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 04:02:11 hn-dlp setroubleshoot[13697]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-010000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-010000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 04:02:12 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:02:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:02:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 496. Jan 10 04:02:24 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:02:24 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:02:27 hn-dlp platform-python[13713]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:02:27 hn-dlp platform-python[13713]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:02:27 hn-dlp platform-python[13713]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:02:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13713]: new replica keys in LDAP: set() Jan 10 04:02:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13713]: obsolete replica keys in local HSM: set() Jan 10 04:02:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13713]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:02:27 hn-dlp ipa-ods-exporter[13713]: Traceback (most recent call last): Jan 10 04:02:27 hn-dlp ipa-ods-exporter[13713]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:02:27 hn-dlp ipa-ods-exporter[13713]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:02:27 hn-dlp ipa-ods-exporter[13713]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:02:27 hn-dlp ipa-ods-exporter[13713]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:02:27 hn-dlp ipa-ods-exporter[13713]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:02:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:02:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:03:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:03:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:03:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:03:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 497. Jan 10 04:03:28 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:03:28 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:03:30 hn-dlp platform-python[13721]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:03:30 hn-dlp platform-python[13721]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:03:30 hn-dlp platform-python[13721]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:03:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13721]: new replica keys in LDAP: set() Jan 10 04:03:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13721]: obsolete replica keys in local HSM: set() Jan 10 04:03:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13721]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:03:30 hn-dlp ipa-ods-exporter[13721]: Traceback (most recent call last): Jan 10 04:03:30 hn-dlp ipa-ods-exporter[13721]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:03:30 hn-dlp ipa-ods-exporter[13721]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:03:30 hn-dlp ipa-ods-exporter[13721]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:03:30 hn-dlp ipa-ods-exporter[13721]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:03:30 hn-dlp ipa-ods-exporter[13721]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:03:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:03:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:04:13 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:04:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:04:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 498. Jan 10 04:04:31 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:04:31 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:04:33 hn-dlp platform-python[13732]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:04:33 hn-dlp platform-python[13732]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:04:33 hn-dlp platform-python[13732]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:04:34 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13732]: new replica keys in LDAP: set() Jan 10 04:04:34 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13732]: obsolete replica keys in local HSM: set() Jan 10 04:04:34 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13732]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:04:34 hn-dlp ipa-ods-exporter[13732]: Traceback (most recent call last): Jan 10 04:04:34 hn-dlp ipa-ods-exporter[13732]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:04:34 hn-dlp ipa-ods-exporter[13732]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:04:34 hn-dlp ipa-ods-exporter[13732]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:04:34 hn-dlp ipa-ods-exporter[13732]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:04:34 hn-dlp ipa-ods-exporter[13732]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:04:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:04:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:05:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:05:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:05:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:05:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 499. Jan 10 04:05:34 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:05:34 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:05:37 hn-dlp platform-python[13743]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:05:37 hn-dlp platform-python[13743]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:05:37 hn-dlp platform-python[13743]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:05:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13743]: new replica keys in LDAP: set() Jan 10 04:05:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13743]: obsolete replica keys in local HSM: set() Jan 10 04:05:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13743]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:05:37 hn-dlp ipa-ods-exporter[13743]: Traceback (most recent call last): Jan 10 04:05:37 hn-dlp ipa-ods-exporter[13743]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:05:37 hn-dlp ipa-ods-exporter[13743]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:05:37 hn-dlp ipa-ods-exporter[13743]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:05:37 hn-dlp ipa-ods-exporter[13743]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:05:37 hn-dlp ipa-ods-exporter[13743]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:05:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:05:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:06:13 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:06:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:06:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 500. Jan 10 04:06:37 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:06:37 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:06:40 hn-dlp platform-python[13751]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:06:40 hn-dlp platform-python[13751]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:06:40 hn-dlp platform-python[13751]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:06:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13751]: new replica keys in LDAP: set() Jan 10 04:06:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13751]: obsolete replica keys in local HSM: set() Jan 10 04:06:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13751]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:06:40 hn-dlp ipa-ods-exporter[13751]: Traceback (most recent call last): Jan 10 04:06:40 hn-dlp ipa-ods-exporter[13751]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:06:40 hn-dlp ipa-ods-exporter[13751]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:06:40 hn-dlp ipa-ods-exporter[13751]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:06:40 hn-dlp ipa-ods-exporter[13751]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:06:40 hn-dlp ipa-ods-exporter[13751]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:06:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:06:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:07:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:07:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:07:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:07:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 501. Jan 10 04:07:41 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:07:41 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:07:43 hn-dlp platform-python[13761]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:07:43 hn-dlp platform-python[13761]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:07:43 hn-dlp platform-python[13761]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:07:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13761]: new replica keys in LDAP: set() Jan 10 04:07:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13761]: obsolete replica keys in local HSM: set() Jan 10 04:07:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13761]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:07:43 hn-dlp ipa-ods-exporter[13761]: Traceback (most recent call last): Jan 10 04:07:43 hn-dlp ipa-ods-exporter[13761]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:07:43 hn-dlp ipa-ods-exporter[13761]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:07:43 hn-dlp ipa-ods-exporter[13761]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:07:43 hn-dlp ipa-ods-exporter[13761]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:07:43 hn-dlp ipa-ods-exporter[13761]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:07:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:07:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:08:13 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:08:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:08:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 502. Jan 10 04:08:44 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:08:44 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:08:46 hn-dlp platform-python[13769]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:08:46 hn-dlp platform-python[13769]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:08:46 hn-dlp platform-python[13769]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:08:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13769]: new replica keys in LDAP: set() Jan 10 04:08:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13769]: obsolete replica keys in local HSM: set() Jan 10 04:08:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13769]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:08:47 hn-dlp ipa-ods-exporter[13769]: Traceback (most recent call last): Jan 10 04:08:47 hn-dlp ipa-ods-exporter[13769]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:08:47 hn-dlp ipa-ods-exporter[13769]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:08:47 hn-dlp ipa-ods-exporter[13769]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:08:47 hn-dlp ipa-ods-exporter[13769]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:08:47 hn-dlp ipa-ods-exporter[13769]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:08:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:08:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:09:13 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 04:09:13 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:09:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:09:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 503. Jan 10 04:09:47 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:09:47 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:09:49 hn-dlp platform-python[13779]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:09:49 hn-dlp platform-python[13779]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:09:49 hn-dlp platform-python[13779]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:09:50 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13779]: new replica keys in LDAP: set() Jan 10 04:09:50 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13779]: obsolete replica keys in local HSM: set() Jan 10 04:09:50 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13779]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:09:50 hn-dlp ipa-ods-exporter[13779]: Traceback (most recent call last): Jan 10 04:09:50 hn-dlp ipa-ods-exporter[13779]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:09:50 hn-dlp ipa-ods-exporter[13779]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:09:50 hn-dlp ipa-ods-exporter[13779]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:09:50 hn-dlp ipa-ods-exporter[13779]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:09:50 hn-dlp ipa-ods-exporter[13779]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:09:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:09:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:10:13 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:10:34 hn-dlp named-pkcs11[1516]: client @0x7fb2f4118410 172.19.186.212#59391 (197.19.172.in-addr.arpa): transfer of '197.19.172.in-addr.arpa/IN': AXFR-style IXFR started (serial 1610244981) Jan 10 04:10:34 hn-dlp named-pkcs11[1516]: client @0x7fb2f4118410 172.19.186.212#59391 (197.19.172.in-addr.arpa): transfer of '197.19.172.in-addr.arpa/IN': AXFR-style IXFR ended Jan 10 04:10:40 hn-dlp named-pkcs11[1516]: client @0x7fb2f4043e40 172.19.186.212#59394 (ipa.example.local): transfer of 'ipa.example.local/IN': AXFR-style IXFR started (serial 1610244980) Jan 10 04:10:40 hn-dlp named-pkcs11[1516]: client @0x7fb2f4043e40 172.19.186.212#59394 (ipa.example.local): transfer of 'ipa.example.local/IN': AXFR-style IXFR ended Jan 10 04:10:45 hn-dlp named-pkcs11[1516]: client @0x7fb2dd13c230 172.19.186.212#59396 (177.19.172.in-addr.arpa): transfer of '177.19.172.in-addr.arpa/IN': AXFR-style IXFR started (serial 1610244981) Jan 10 04:10:45 hn-dlp named-pkcs11[1516]: client @0x7fb2dd13c230 172.19.186.212#59396 (177.19.172.in-addr.arpa): transfer of '177.19.172.in-addr.arpa/IN': AXFR-style IXFR ended Jan 10 04:10:45 hn-dlp named-pkcs11[1516]: client @0x7fb2f4118410 172.19.186.212#59397 (187.19.172.in-addr.arpa): transfer of '187.19.172.in-addr.arpa/IN': AXFR-style IXFR started (serial 1610244981) Jan 10 04:10:45 hn-dlp named-pkcs11[1516]: client @0x7fb2f4118410 172.19.186.212#59397 (187.19.172.in-addr.arpa): transfer of '187.19.172.in-addr.arpa/IN': AXFR-style IXFR ended Jan 10 04:10:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:10:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 504. Jan 10 04:10:50 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:10:50 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:10:53 hn-dlp platform-python[13788]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:10:53 hn-dlp platform-python[13788]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:10:53 hn-dlp platform-python[13788]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:10:53 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13788]: new replica keys in LDAP: set() Jan 10 04:10:53 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13788]: obsolete replica keys in local HSM: set() Jan 10 04:10:53 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13788]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:10:53 hn-dlp ipa-ods-exporter[13788]: Traceback (most recent call last): Jan 10 04:10:53 hn-dlp ipa-ods-exporter[13788]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:10:53 hn-dlp ipa-ods-exporter[13788]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:10:53 hn-dlp ipa-ods-exporter[13788]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:10:53 hn-dlp ipa-ods-exporter[13788]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:10:53 hn-dlp ipa-ods-exporter[13788]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:10:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:10:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:11:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:11:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:11:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:11:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 505. Jan 10 04:11:53 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:11:53 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:11:56 hn-dlp platform-python[13799]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:11:56 hn-dlp platform-python[13799]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:11:56 hn-dlp platform-python[13799]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:11:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13799]: new replica keys in LDAP: set() Jan 10 04:11:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13799]: obsolete replica keys in local HSM: set() Jan 10 04:11:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13799]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:11:56 hn-dlp ipa-ods-exporter[13799]: Traceback (most recent call last): Jan 10 04:11:56 hn-dlp ipa-ods-exporter[13799]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:11:56 hn-dlp ipa-ods-exporter[13799]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:11:56 hn-dlp ipa-ods-exporter[13799]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:11:56 hn-dlp ipa-ods-exporter[13799]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:11:56 hn-dlp ipa-ods-exporter[13799]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:11:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:11:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:12:13 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:12:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:12:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 506. Jan 10 04:12:57 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:12:57 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:12:59 hn-dlp platform-python[13807]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:12:59 hn-dlp platform-python[13807]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:12:59 hn-dlp platform-python[13807]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:12:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13807]: new replica keys in LDAP: set() Jan 10 04:12:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13807]: obsolete replica keys in local HSM: set() Jan 10 04:12:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13807]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:12:59 hn-dlp ipa-ods-exporter[13807]: Traceback (most recent call last): Jan 10 04:12:59 hn-dlp ipa-ods-exporter[13807]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:12:59 hn-dlp ipa-ods-exporter[13807]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:12:59 hn-dlp ipa-ods-exporter[13807]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:12:59 hn-dlp ipa-ods-exporter[13807]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:12:59 hn-dlp ipa-ods-exporter[13807]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:13:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:13:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:13:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:13:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:14:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:14:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 507. Jan 10 04:14:00 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:14:00 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:14:02 hn-dlp platform-python[13815]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:14:02 hn-dlp platform-python[13815]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:14:02 hn-dlp platform-python[13815]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:14:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13815]: new replica keys in LDAP: set() Jan 10 04:14:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13815]: obsolete replica keys in local HSM: set() Jan 10 04:14:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13815]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:14:03 hn-dlp ipa-ods-exporter[13815]: Traceback (most recent call last): Jan 10 04:14:03 hn-dlp ipa-ods-exporter[13815]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:14:03 hn-dlp ipa-ods-exporter[13815]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:14:03 hn-dlp ipa-ods-exporter[13815]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:14:03 hn-dlp ipa-ods-exporter[13815]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:14:03 hn-dlp ipa-ods-exporter[13815]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:14:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:14:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:14:13 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:15:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:15:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 508. Jan 10 04:15:03 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:15:03 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:15:06 hn-dlp platform-python[13825]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:15:06 hn-dlp platform-python[13825]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:15:06 hn-dlp platform-python[13825]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:15:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13825]: new replica keys in LDAP: set() Jan 10 04:15:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13825]: obsolete replica keys in local HSM: set() Jan 10 04:15:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13825]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:15:06 hn-dlp ipa-ods-exporter[13825]: Traceback (most recent call last): Jan 10 04:15:06 hn-dlp ipa-ods-exporter[13825]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:15:06 hn-dlp ipa-ods-exporter[13825]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:15:06 hn-dlp ipa-ods-exporter[13825]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:15:06 hn-dlp ipa-ods-exporter[13825]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:15:06 hn-dlp ipa-ods-exporter[13825]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:15:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:15:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:15:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:15:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:16:07 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:16:07 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 509. Jan 10 04:16:07 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:16:07 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:16:09 hn-dlp platform-python[13833]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:16:09 hn-dlp platform-python[13833]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:16:09 hn-dlp platform-python[13833]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:16:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13833]: new replica keys in LDAP: set() Jan 10 04:16:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13833]: obsolete replica keys in local HSM: set() Jan 10 04:16:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13833]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:16:09 hn-dlp ipa-ods-exporter[13833]: Traceback (most recent call last): Jan 10 04:16:09 hn-dlp ipa-ods-exporter[13833]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:16:09 hn-dlp ipa-ods-exporter[13833]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:16:09 hn-dlp ipa-ods-exporter[13833]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:16:09 hn-dlp ipa-ods-exporter[13833]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:16:09 hn-dlp ipa-ods-exporter[13833]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:16:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:16:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:16:13 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:17:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:17:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 510. Jan 10 04:17:10 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:17:10 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:17:12 hn-dlp platform-python[13844]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:17:12 hn-dlp platform-python[13844]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:17:12 hn-dlp platform-python[13844]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:17:13 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13844]: new replica keys in LDAP: set() Jan 10 04:17:13 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13844]: obsolete replica keys in local HSM: set() Jan 10 04:17:13 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13844]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:17:13 hn-dlp ipa-ods-exporter[13844]: Traceback (most recent call last): Jan 10 04:17:13 hn-dlp ipa-ods-exporter[13844]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:17:13 hn-dlp ipa-ods-exporter[13844]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:17:13 hn-dlp ipa-ods-exporter[13844]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:17:13 hn-dlp ipa-ods-exporter[13844]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:17:13 hn-dlp ipa-ods-exporter[13844]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:17:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:17:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:17:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:17:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:18:13 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:18:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:18:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 511. Jan 10 04:18:13 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:18:13 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:18:16 hn-dlp platform-python[13853]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:18:16 hn-dlp platform-python[13853]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:18:16 hn-dlp platform-python[13853]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:18:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13853]: new replica keys in LDAP: set() Jan 10 04:18:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13853]: obsolete replica keys in local HSM: set() Jan 10 04:18:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13853]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:18:16 hn-dlp ipa-ods-exporter[13853]: Traceback (most recent call last): Jan 10 04:18:16 hn-dlp ipa-ods-exporter[13853]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:18:16 hn-dlp ipa-ods-exporter[13853]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:18:16 hn-dlp ipa-ods-exporter[13853]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:18:16 hn-dlp ipa-ods-exporter[13853]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:18:16 hn-dlp ipa-ods-exporter[13853]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:18:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:18:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:19:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:19:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:19:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:19:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 512. Jan 10 04:19:16 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:19:16 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:19:19 hn-dlp platform-python[13864]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:19:19 hn-dlp platform-python[13864]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:19:19 hn-dlp platform-python[13864]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:19:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13864]: new replica keys in LDAP: set() Jan 10 04:19:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13864]: obsolete replica keys in local HSM: set() Jan 10 04:19:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13864]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:19:19 hn-dlp ipa-ods-exporter[13864]: Traceback (most recent call last): Jan 10 04:19:19 hn-dlp ipa-ods-exporter[13864]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:19:19 hn-dlp ipa-ods-exporter[13864]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:19:19 hn-dlp ipa-ods-exporter[13864]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:19:19 hn-dlp ipa-ods-exporter[13864]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:19:19 hn-dlp ipa-ods-exporter[13864]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:19:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:19:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:20:13 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:20:20 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:20:20 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 513. Jan 10 04:20:20 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:20:20 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:20:22 hn-dlp platform-python[13875]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:20:22 hn-dlp platform-python[13875]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:20:22 hn-dlp platform-python[13875]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:20:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13875]: new replica keys in LDAP: set() Jan 10 04:20:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13875]: obsolete replica keys in local HSM: set() Jan 10 04:20:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13875]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:20:22 hn-dlp ipa-ods-exporter[13875]: Traceback (most recent call last): Jan 10 04:20:22 hn-dlp ipa-ods-exporter[13875]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:20:22 hn-dlp ipa-ods-exporter[13875]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:20:22 hn-dlp ipa-ods-exporter[13875]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:20:22 hn-dlp ipa-ods-exporter[13875]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:20:22 hn-dlp ipa-ods-exporter[13875]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:20:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:20:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:21:13 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 04:21:13 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:21:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:21:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 514. Jan 10 04:21:23 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:21:23 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:21:25 hn-dlp platform-python[13885]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:21:25 hn-dlp platform-python[13885]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:21:25 hn-dlp platform-python[13885]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:21:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13885]: new replica keys in LDAP: set() Jan 10 04:21:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13885]: obsolete replica keys in local HSM: set() Jan 10 04:21:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13885]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:21:26 hn-dlp ipa-ods-exporter[13885]: Traceback (most recent call last): Jan 10 04:21:26 hn-dlp ipa-ods-exporter[13885]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:21:26 hn-dlp ipa-ods-exporter[13885]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:21:26 hn-dlp ipa-ods-exporter[13885]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:21:26 hn-dlp ipa-ods-exporter[13885]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:21:26 hn-dlp ipa-ods-exporter[13885]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:21:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:21:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:22:13 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:22:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:22:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 515. Jan 10 04:22:26 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:22:26 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:22:28 hn-dlp platform-python[13893]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:22:28 hn-dlp platform-python[13893]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:22:28 hn-dlp platform-python[13893]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:22:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13893]: new replica keys in LDAP: set() Jan 10 04:22:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13893]: obsolete replica keys in local HSM: set() Jan 10 04:22:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13893]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:22:29 hn-dlp ipa-ods-exporter[13893]: Traceback (most recent call last): Jan 10 04:22:29 hn-dlp ipa-ods-exporter[13893]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:22:29 hn-dlp ipa-ods-exporter[13893]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:22:29 hn-dlp ipa-ods-exporter[13893]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:22:29 hn-dlp ipa-ods-exporter[13893]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:22:29 hn-dlp ipa-ods-exporter[13893]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:22:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:22:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:23:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:23:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:23:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:23:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 516. Jan 10 04:23:29 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:23:29 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:23:32 hn-dlp platform-python[13904]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:23:32 hn-dlp platform-python[13904]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:23:32 hn-dlp platform-python[13904]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:23:32 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13904]: new replica keys in LDAP: set() Jan 10 04:23:32 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13904]: obsolete replica keys in local HSM: set() Jan 10 04:23:32 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13904]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:23:32 hn-dlp ipa-ods-exporter[13904]: Traceback (most recent call last): Jan 10 04:23:32 hn-dlp ipa-ods-exporter[13904]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:23:32 hn-dlp ipa-ods-exporter[13904]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:23:32 hn-dlp ipa-ods-exporter[13904]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:23:32 hn-dlp ipa-ods-exporter[13904]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:23:32 hn-dlp ipa-ods-exporter[13904]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:23:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:23:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:24:13 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:24:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:24:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 517. Jan 10 04:24:32 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:24:32 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:24:35 hn-dlp platform-python[13914]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:24:35 hn-dlp platform-python[13914]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:24:35 hn-dlp platform-python[13914]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:24:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13914]: new replica keys in LDAP: set() Jan 10 04:24:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13914]: obsolete replica keys in local HSM: set() Jan 10 04:24:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13914]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:24:35 hn-dlp ipa-ods-exporter[13914]: Traceback (most recent call last): Jan 10 04:24:35 hn-dlp ipa-ods-exporter[13914]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:24:35 hn-dlp ipa-ods-exporter[13914]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:24:35 hn-dlp ipa-ods-exporter[13914]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:24:35 hn-dlp ipa-ods-exporter[13914]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:24:35 hn-dlp ipa-ods-exporter[13914]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:24:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:24:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:25:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:25:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:25:36 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:25:36 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 518. Jan 10 04:25:36 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:25:36 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:25:38 hn-dlp platform-python[13923]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:25:38 hn-dlp platform-python[13923]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:25:38 hn-dlp platform-python[13923]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:25:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13923]: new replica keys in LDAP: set() Jan 10 04:25:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13923]: obsolete replica keys in local HSM: set() Jan 10 04:25:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13923]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:25:38 hn-dlp ipa-ods-exporter[13923]: Traceback (most recent call last): Jan 10 04:25:38 hn-dlp ipa-ods-exporter[13923]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:25:38 hn-dlp ipa-ods-exporter[13923]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:25:38 hn-dlp ipa-ods-exporter[13923]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:25:38 hn-dlp ipa-ods-exporter[13923]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:25:38 hn-dlp ipa-ods-exporter[13923]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:25:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:25:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:26:13 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:26:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:26:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 519. Jan 10 04:26:39 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:26:39 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:26:41 hn-dlp platform-python[13934]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:26:41 hn-dlp platform-python[13934]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:26:41 hn-dlp platform-python[13934]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:26:42 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13934]: new replica keys in LDAP: set() Jan 10 04:26:42 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13934]: obsolete replica keys in local HSM: set() Jan 10 04:26:42 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13934]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:26:42 hn-dlp ipa-ods-exporter[13934]: Traceback (most recent call last): Jan 10 04:26:42 hn-dlp ipa-ods-exporter[13934]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:26:42 hn-dlp ipa-ods-exporter[13934]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:26:42 hn-dlp ipa-ods-exporter[13934]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:26:42 hn-dlp ipa-ods-exporter[13934]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:26:42 hn-dlp ipa-ods-exporter[13934]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:26:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:26:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:27:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:27:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:27:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:27:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 520. Jan 10 04:27:42 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:27:42 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:27:44 hn-dlp platform-python[13943]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:27:44 hn-dlp platform-python[13943]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:27:44 hn-dlp platform-python[13943]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:27:45 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13943]: new replica keys in LDAP: set() Jan 10 04:27:45 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13943]: obsolete replica keys in local HSM: set() Jan 10 04:27:45 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13943]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:27:45 hn-dlp ipa-ods-exporter[13943]: Traceback (most recent call last): Jan 10 04:27:45 hn-dlp ipa-ods-exporter[13943]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:27:45 hn-dlp ipa-ods-exporter[13943]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:27:45 hn-dlp ipa-ods-exporter[13943]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:27:45 hn-dlp ipa-ods-exporter[13943]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:27:45 hn-dlp ipa-ods-exporter[13943]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:27:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:27:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:28:13 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:28:33 hn-dlp systemd[1]: Starting dnf makecache... Jan 10 04:28:36 hn-dlp dnf[13952]: Updating Subscription Management repositories. Jan 10 04:28:37 hn-dlp dnf[13952]: Metadata cache refreshed recently. Jan 10 04:28:37 hn-dlp systemd[1]: dnf-makecache.service: Succeeded. Jan 10 04:28:37 hn-dlp systemd[1]: Started dnf makecache. Jan 10 04:28:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:28:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 521. Jan 10 04:28:45 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:28:45 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:28:48 hn-dlp platform-python[13957]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:28:48 hn-dlp platform-python[13957]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:28:48 hn-dlp platform-python[13957]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:28:48 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13957]: new replica keys in LDAP: set() Jan 10 04:28:48 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13957]: obsolete replica keys in local HSM: set() Jan 10 04:28:48 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13957]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:28:48 hn-dlp ipa-ods-exporter[13957]: Traceback (most recent call last): Jan 10 04:28:48 hn-dlp ipa-ods-exporter[13957]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:28:48 hn-dlp ipa-ods-exporter[13957]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:28:48 hn-dlp ipa-ods-exporter[13957]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:28:48 hn-dlp ipa-ods-exporter[13957]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:28:48 hn-dlp ipa-ods-exporter[13957]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:28:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:28:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:29:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:29:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:29:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:29:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 522. Jan 10 04:29:49 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:29:49 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:29:51 hn-dlp platform-python[13968]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:29:51 hn-dlp platform-python[13968]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:29:51 hn-dlp platform-python[13968]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:29:51 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13968]: new replica keys in LDAP: set() Jan 10 04:29:51 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13968]: obsolete replica keys in local HSM: set() Jan 10 04:29:51 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[13968]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:29:51 hn-dlp ipa-ods-exporter[13968]: Traceback (most recent call last): Jan 10 04:29:51 hn-dlp ipa-ods-exporter[13968]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:29:51 hn-dlp ipa-ods-exporter[13968]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:29:51 hn-dlp ipa-ods-exporter[13968]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:29:51 hn-dlp ipa-ods-exporter[13968]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:29:51 hn-dlp ipa-ods-exporter[13968]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:29:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:29:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:30:13 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:30:31 hn-dlp systemd[1]: Created slice User Slice of UID 2002. Jan 10 04:30:31 hn-dlp systemd[1]: Started /run/user/2002 mount wrapper. Jan 10 04:30:31 hn-dlp systemd[1]: Starting User Manager for UID 2002... Jan 10 04:30:31 hn-dlp systemd[1]: Started Session 40 of user svcforeman. Jan 10 04:30:31 hn-dlp systemd-logind[736]: New session 40 of user svcforeman. Jan 10 04:30:31 hn-dlp systemd[13982]: Started Mark boot as successful after the user session has run 2 minutes. Jan 10 04:30:31 hn-dlp systemd[13982]: Reached target Timers. Jan 10 04:30:31 hn-dlp systemd[13982]: Reached target Paths. Jan 10 04:30:31 hn-dlp systemd[13982]: Starting D-Bus User Message Bus Socket. Jan 10 04:30:31 hn-dlp systemd[13982]: Listening on D-Bus User Message Bus Socket. Jan 10 04:30:31 hn-dlp systemd[13982]: Reached target Sockets. Jan 10 04:30:31 hn-dlp systemd[13982]: Reached target Basic System. Jan 10 04:30:31 hn-dlp systemd[13982]: Reached target Default. Jan 10 04:30:31 hn-dlp systemd[13982]: Startup finished in 132ms. Jan 10 04:30:31 hn-dlp systemd[1]: Started User Manager for UID 2002. Jan 10 04:30:34 hn-dlp platform-python[14144]: ansible-setup Invoked with gather_timeout=10 gather_subset=['all'] filter=* fact_path=/etc/ansible/facts.d Jan 10 04:30:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:30:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 523. Jan 10 04:30:52 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:30:52 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:30:54 hn-dlp platform-python[14249]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:30:54 hn-dlp platform-python[14249]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:30:54 hn-dlp platform-python[14249]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:30:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14249]: new replica keys in LDAP: set() Jan 10 04:30:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14249]: obsolete replica keys in local HSM: set() Jan 10 04:30:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14249]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:30:55 hn-dlp ipa-ods-exporter[14249]: Traceback (most recent call last): Jan 10 04:30:55 hn-dlp ipa-ods-exporter[14249]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:30:55 hn-dlp ipa-ods-exporter[14249]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:30:55 hn-dlp ipa-ods-exporter[14249]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:30:55 hn-dlp ipa-ods-exporter[14249]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:30:55 hn-dlp ipa-ods-exporter[14249]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:30:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:30:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:31:13 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 04:31:13 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:31:40 hn-dlp systemd[1]: session-40.scope: Succeeded. Jan 10 04:31:40 hn-dlp systemd-logind[736]: Session 40 logged out. Waiting for processes to exit. Jan 10 04:31:40 hn-dlp systemd-logind[736]: Removed session 40. Jan 10 04:31:40 hn-dlp systemd[1]: Stopping User Manager for UID 2002... Jan 10 04:31:40 hn-dlp systemd[13982]: Stopped target Default. Jan 10 04:31:40 hn-dlp systemd[13982]: Stopped target Basic System. Jan 10 04:31:40 hn-dlp systemd[13982]: Stopped target Paths. Jan 10 04:31:40 hn-dlp systemd[13982]: Stopped target Sockets. Jan 10 04:31:40 hn-dlp systemd[13982]: dbus.socket: Succeeded. Jan 10 04:31:40 hn-dlp systemd[13982]: Closed D-Bus User Message Bus Socket. Jan 10 04:31:40 hn-dlp systemd[13982]: Stopped target Timers. Jan 10 04:31:40 hn-dlp systemd[13982]: grub-boot-success.timer: Succeeded. Jan 10 04:31:40 hn-dlp systemd[13982]: Stopped Mark boot as successful after the user session has run 2 minutes. Jan 10 04:31:40 hn-dlp systemd[13982]: Reached target Shutdown. Jan 10 04:31:40 hn-dlp systemd[13982]: Starting Exit the Session... Jan 10 04:31:40 hn-dlp systemd[1]: user@2002.service: Succeeded. Jan 10 04:31:40 hn-dlp systemd[1]: Stopped User Manager for UID 2002. Jan 10 04:31:40 hn-dlp systemd[1]: Stopping /run/user/2002 mount wrapper... Jan 10 04:31:40 hn-dlp systemd[1]: Removed slice User Slice of UID 2002. Jan 10 04:31:40 hn-dlp systemd[1]: run-user-2002.mount: Succeeded. Jan 10 04:31:40 hn-dlp systemd[1]: user-runtime-dir@2002.service: Succeeded. Jan 10 04:31:40 hn-dlp systemd[1]: Stopped /run/user/2002 mount wrapper. Jan 10 04:31:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:31:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 524. Jan 10 04:31:55 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:31:55 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:31:58 hn-dlp platform-python[14271]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:31:58 hn-dlp platform-python[14271]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:31:58 hn-dlp platform-python[14271]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:31:58 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14271]: new replica keys in LDAP: set() Jan 10 04:31:58 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14271]: obsolete replica keys in local HSM: set() Jan 10 04:31:58 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14271]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:31:58 hn-dlp ipa-ods-exporter[14271]: Traceback (most recent call last): Jan 10 04:31:58 hn-dlp ipa-ods-exporter[14271]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:31:58 hn-dlp ipa-ods-exporter[14271]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:31:58 hn-dlp ipa-ods-exporter[14271]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:31:58 hn-dlp ipa-ods-exporter[14271]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:31:58 hn-dlp ipa-ods-exporter[14271]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:31:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:31:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:32:13 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:32:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:32:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 525. Jan 10 04:32:58 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:32:58 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:33:01 hn-dlp platform-python[14279]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:33:01 hn-dlp platform-python[14279]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:33:01 hn-dlp platform-python[14279]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:33:01 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14279]: new replica keys in LDAP: set() Jan 10 04:33:01 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14279]: obsolete replica keys in local HSM: set() Jan 10 04:33:01 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14279]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:33:01 hn-dlp ipa-ods-exporter[14279]: Traceback (most recent call last): Jan 10 04:33:01 hn-dlp ipa-ods-exporter[14279]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:33:01 hn-dlp ipa-ods-exporter[14279]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:33:01 hn-dlp ipa-ods-exporter[14279]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:33:01 hn-dlp ipa-ods-exporter[14279]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:33:01 hn-dlp ipa-ods-exporter[14279]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:33:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:33:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:33:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:33:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:34:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:34:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 526. Jan 10 04:34:01 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:34:01 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:34:04 hn-dlp platform-python[14289]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:34:04 hn-dlp platform-python[14289]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:34:04 hn-dlp platform-python[14289]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:34:04 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14289]: new replica keys in LDAP: set() Jan 10 04:34:04 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14289]: obsolete replica keys in local HSM: set() Jan 10 04:34:04 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14289]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:34:04 hn-dlp ipa-ods-exporter[14289]: Traceback (most recent call last): Jan 10 04:34:04 hn-dlp ipa-ods-exporter[14289]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:34:04 hn-dlp ipa-ods-exporter[14289]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:34:04 hn-dlp ipa-ods-exporter[14289]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:34:04 hn-dlp ipa-ods-exporter[14289]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:34:04 hn-dlp ipa-ods-exporter[14289]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:34:04 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:34:04 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:34:14 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:35:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:35:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 527. Jan 10 04:35:05 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:35:05 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:35:07 hn-dlp platform-python[14300]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:35:07 hn-dlp platform-python[14300]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:35:07 hn-dlp platform-python[14300]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:35:07 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14300]: new replica keys in LDAP: set() Jan 10 04:35:07 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14300]: obsolete replica keys in local HSM: set() Jan 10 04:35:07 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14300]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:35:07 hn-dlp ipa-ods-exporter[14300]: Traceback (most recent call last): Jan 10 04:35:07 hn-dlp ipa-ods-exporter[14300]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:35:07 hn-dlp ipa-ods-exporter[14300]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:35:07 hn-dlp ipa-ods-exporter[14300]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:35:07 hn-dlp ipa-ods-exporter[14300]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:35:07 hn-dlp ipa-ods-exporter[14300]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:35:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:35:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:35:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:35:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:36:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:36:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 528. Jan 10 04:36:08 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:36:08 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:36:10 hn-dlp platform-python[14308]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:36:10 hn-dlp platform-python[14308]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:36:10 hn-dlp platform-python[14308]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:36:11 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14308]: new replica keys in LDAP: set() Jan 10 04:36:11 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14308]: obsolete replica keys in local HSM: set() Jan 10 04:36:11 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14308]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:36:11 hn-dlp ipa-ods-exporter[14308]: Traceback (most recent call last): Jan 10 04:36:11 hn-dlp ipa-ods-exporter[14308]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:36:11 hn-dlp ipa-ods-exporter[14308]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:36:11 hn-dlp ipa-ods-exporter[14308]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:36:11 hn-dlp ipa-ods-exporter[14308]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:36:11 hn-dlp ipa-ods-exporter[14308]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:36:11 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:36:11 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:36:14 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:37:11 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:37:11 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 529. Jan 10 04:37:11 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:37:11 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:37:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:37:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:37:14 hn-dlp platform-python[14319]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:37:14 hn-dlp platform-python[14319]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:37:14 hn-dlp platform-python[14319]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:37:14 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14319]: new replica keys in LDAP: set() Jan 10 04:37:14 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14319]: obsolete replica keys in local HSM: set() Jan 10 04:37:14 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14319]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:37:14 hn-dlp ipa-ods-exporter[14319]: Traceback (most recent call last): Jan 10 04:37:14 hn-dlp ipa-ods-exporter[14319]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:37:14 hn-dlp ipa-ods-exporter[14319]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:37:14 hn-dlp ipa-ods-exporter[14319]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:37:14 hn-dlp ipa-ods-exporter[14319]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:37:14 hn-dlp ipa-ods-exporter[14319]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:37:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:37:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:38:14 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:38:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:38:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 530. Jan 10 04:38:14 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:38:14 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:38:17 hn-dlp platform-python[14328]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:38:17 hn-dlp platform-python[14328]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:38:17 hn-dlp platform-python[14328]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:38:17 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14328]: new replica keys in LDAP: set() Jan 10 04:38:17 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14328]: obsolete replica keys in local HSM: set() Jan 10 04:38:17 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14328]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:38:17 hn-dlp ipa-ods-exporter[14328]: Traceback (most recent call last): Jan 10 04:38:17 hn-dlp ipa-ods-exporter[14328]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:38:17 hn-dlp ipa-ods-exporter[14328]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:38:17 hn-dlp ipa-ods-exporter[14328]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:38:17 hn-dlp ipa-ods-exporter[14328]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:38:17 hn-dlp ipa-ods-exporter[14328]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:38:17 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:38:17 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:39:13 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:39:13 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:39:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:39:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 531. Jan 10 04:39:18 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:39:18 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:39:20 hn-dlp platform-python[14337]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:39:20 hn-dlp platform-python[14337]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:39:20 hn-dlp platform-python[14337]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:39:20 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14337]: new replica keys in LDAP: set() Jan 10 04:39:20 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14337]: obsolete replica keys in local HSM: set() Jan 10 04:39:20 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14337]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:39:20 hn-dlp ipa-ods-exporter[14337]: Traceback (most recent call last): Jan 10 04:39:20 hn-dlp ipa-ods-exporter[14337]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:39:20 hn-dlp ipa-ods-exporter[14337]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:39:20 hn-dlp ipa-ods-exporter[14337]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:39:20 hn-dlp ipa-ods-exporter[14337]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:39:20 hn-dlp ipa-ods-exporter[14337]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:39:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:39:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:40:14 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:40:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:40:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 532. Jan 10 04:40:21 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:40:21 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:40:23 hn-dlp platform-python[14347]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:40:23 hn-dlp platform-python[14347]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:40:23 hn-dlp platform-python[14347]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:40:24 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14347]: new replica keys in LDAP: set() Jan 10 04:40:24 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14347]: obsolete replica keys in local HSM: set() Jan 10 04:40:24 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14347]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:40:24 hn-dlp ipa-ods-exporter[14347]: Traceback (most recent call last): Jan 10 04:40:24 hn-dlp ipa-ods-exporter[14347]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:40:24 hn-dlp ipa-ods-exporter[14347]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:40:24 hn-dlp ipa-ods-exporter[14347]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:40:24 hn-dlp ipa-ods-exporter[14347]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:40:24 hn-dlp ipa-ods-exporter[14347]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:40:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:40:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:41:14 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 04:41:14 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:41:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:41:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 533. Jan 10 04:41:24 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:41:24 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:41:26 hn-dlp platform-python[14358]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:41:26 hn-dlp platform-python[14358]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:41:26 hn-dlp platform-python[14358]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:41:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14358]: new replica keys in LDAP: set() Jan 10 04:41:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14358]: obsolete replica keys in local HSM: set() Jan 10 04:41:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14358]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:41:27 hn-dlp ipa-ods-exporter[14358]: Traceback (most recent call last): Jan 10 04:41:27 hn-dlp ipa-ods-exporter[14358]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:41:27 hn-dlp ipa-ods-exporter[14358]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:41:27 hn-dlp ipa-ods-exporter[14358]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:41:27 hn-dlp ipa-ods-exporter[14358]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:41:27 hn-dlp ipa-ods-exporter[14358]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:41:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:41:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:42:14 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:42:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:42:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 534. Jan 10 04:42:27 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:42:27 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:42:30 hn-dlp platform-python[14368]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:42:30 hn-dlp platform-python[14368]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:42:30 hn-dlp platform-python[14368]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:42:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14368]: new replica keys in LDAP: set() Jan 10 04:42:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14368]: obsolete replica keys in local HSM: set() Jan 10 04:42:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14368]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:42:30 hn-dlp ipa-ods-exporter[14368]: Traceback (most recent call last): Jan 10 04:42:30 hn-dlp ipa-ods-exporter[14368]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:42:30 hn-dlp ipa-ods-exporter[14368]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:42:30 hn-dlp ipa-ods-exporter[14368]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:42:30 hn-dlp ipa-ods-exporter[14368]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:42:30 hn-dlp ipa-ods-exporter[14368]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:42:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:42:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:43:14 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:43:14 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:43:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:43:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 535. Jan 10 04:43:30 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:43:30 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:43:33 hn-dlp platform-python[14377]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:43:33 hn-dlp platform-python[14377]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:43:33 hn-dlp platform-python[14377]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:43:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14377]: new replica keys in LDAP: set() Jan 10 04:43:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14377]: obsolete replica keys in local HSM: set() Jan 10 04:43:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14377]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:43:33 hn-dlp ipa-ods-exporter[14377]: Traceback (most recent call last): Jan 10 04:43:33 hn-dlp ipa-ods-exporter[14377]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:43:33 hn-dlp ipa-ods-exporter[14377]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:43:33 hn-dlp ipa-ods-exporter[14377]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:43:33 hn-dlp ipa-ods-exporter[14377]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:43:33 hn-dlp ipa-ods-exporter[14377]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:43:33 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:43:33 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:44:14 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:44:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:44:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 536. Jan 10 04:44:34 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:44:34 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:44:36 hn-dlp platform-python[14386]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:44:36 hn-dlp platform-python[14386]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:44:36 hn-dlp platform-python[14386]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:44:36 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14386]: new replica keys in LDAP: set() Jan 10 04:44:36 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14386]: obsolete replica keys in local HSM: set() Jan 10 04:44:36 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14386]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:44:36 hn-dlp ipa-ods-exporter[14386]: Traceback (most recent call last): Jan 10 04:44:36 hn-dlp ipa-ods-exporter[14386]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:44:36 hn-dlp ipa-ods-exporter[14386]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:44:36 hn-dlp ipa-ods-exporter[14386]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:44:36 hn-dlp ipa-ods-exporter[14386]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:44:36 hn-dlp ipa-ods-exporter[14386]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:44:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:44:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:45:14 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:45:14 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:45:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:45:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 537. Jan 10 04:45:37 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:45:37 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:45:39 hn-dlp platform-python[14396]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:45:39 hn-dlp platform-python[14396]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:45:39 hn-dlp platform-python[14396]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:45:39 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14396]: new replica keys in LDAP: set() Jan 10 04:45:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14396]: obsolete replica keys in local HSM: set() Jan 10 04:45:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14396]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:45:40 hn-dlp ipa-ods-exporter[14396]: Traceback (most recent call last): Jan 10 04:45:40 hn-dlp ipa-ods-exporter[14396]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:45:40 hn-dlp ipa-ods-exporter[14396]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:45:40 hn-dlp ipa-ods-exporter[14396]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:45:40 hn-dlp ipa-ods-exporter[14396]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:45:40 hn-dlp ipa-ods-exporter[14396]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:45:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:45:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:46:14 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:46:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:46:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 538. Jan 10 04:46:40 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:46:40 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:46:41 hn-dlp rsyslogd[1013]: imjournal: journal files changed, reloading... [v8.1911.0-6.el8 try https://www.rsyslog.com/e/0 ] Jan 10 04:46:42 hn-dlp platform-python[14404]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:46:42 hn-dlp platform-python[14404]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:46:42 hn-dlp platform-python[14404]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:46:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14404]: new replica keys in LDAP: set() Jan 10 04:46:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14404]: obsolete replica keys in local HSM: set() Jan 10 04:46:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14404]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:46:43 hn-dlp ipa-ods-exporter[14404]: Traceback (most recent call last): Jan 10 04:46:43 hn-dlp ipa-ods-exporter[14404]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:46:43 hn-dlp ipa-ods-exporter[14404]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:46:43 hn-dlp ipa-ods-exporter[14404]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:46:43 hn-dlp ipa-ods-exporter[14404]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:46:43 hn-dlp ipa-ods-exporter[14404]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:46:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:46:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:47:14 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:47:14 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:47:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:47:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 539. Jan 10 04:47:43 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:47:43 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:47:46 hn-dlp platform-python[14414]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:47:46 hn-dlp platform-python[14414]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:47:46 hn-dlp platform-python[14414]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:47:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14414]: new replica keys in LDAP: set() Jan 10 04:47:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14414]: obsolete replica keys in local HSM: set() Jan 10 04:47:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14414]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:47:46 hn-dlp ipa-ods-exporter[14414]: Traceback (most recent call last): Jan 10 04:47:46 hn-dlp ipa-ods-exporter[14414]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:47:46 hn-dlp ipa-ods-exporter[14414]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:47:46 hn-dlp ipa-ods-exporter[14414]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:47:46 hn-dlp ipa-ods-exporter[14414]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:47:46 hn-dlp ipa-ods-exporter[14414]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:47:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:47:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:48:14 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:48:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:48:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 540. Jan 10 04:48:46 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:48:46 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:48:49 hn-dlp platform-python[14424]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:48:49 hn-dlp platform-python[14424]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:48:49 hn-dlp platform-python[14424]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:48:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14424]: new replica keys in LDAP: set() Jan 10 04:48:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14424]: obsolete replica keys in local HSM: set() Jan 10 04:48:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14424]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:48:49 hn-dlp ipa-ods-exporter[14424]: Traceback (most recent call last): Jan 10 04:48:49 hn-dlp ipa-ods-exporter[14424]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:48:49 hn-dlp ipa-ods-exporter[14424]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:48:49 hn-dlp ipa-ods-exporter[14424]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:48:49 hn-dlp ipa-ods-exporter[14424]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:48:49 hn-dlp ipa-ods-exporter[14424]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:48:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:48:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:49:14 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:49:14 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:49:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:49:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 541. Jan 10 04:49:50 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:49:50 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:49:52 hn-dlp platform-python[14435]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:49:52 hn-dlp platform-python[14435]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:49:52 hn-dlp platform-python[14435]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:49:52 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14435]: new replica keys in LDAP: set() Jan 10 04:49:52 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14435]: obsolete replica keys in local HSM: set() Jan 10 04:49:52 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14435]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:49:52 hn-dlp ipa-ods-exporter[14435]: Traceback (most recent call last): Jan 10 04:49:52 hn-dlp ipa-ods-exporter[14435]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:49:52 hn-dlp ipa-ods-exporter[14435]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:49:52 hn-dlp ipa-ods-exporter[14435]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:49:52 hn-dlp ipa-ods-exporter[14435]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:49:52 hn-dlp ipa-ods-exporter[14435]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:49:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:49:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:50:14 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:50:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:50:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 542. Jan 10 04:50:53 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:50:53 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:50:55 hn-dlp platform-python[14446]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:50:55 hn-dlp platform-python[14446]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:50:55 hn-dlp platform-python[14446]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:50:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14446]: new replica keys in LDAP: set() Jan 10 04:50:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14446]: obsolete replica keys in local HSM: set() Jan 10 04:50:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14446]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:50:56 hn-dlp ipa-ods-exporter[14446]: Traceback (most recent call last): Jan 10 04:50:56 hn-dlp ipa-ods-exporter[14446]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:50:56 hn-dlp ipa-ods-exporter[14446]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:50:56 hn-dlp ipa-ods-exporter[14446]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:50:56 hn-dlp ipa-ods-exporter[14446]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:50:56 hn-dlp ipa-ods-exporter[14446]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:50:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:50:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:51:14 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 04:51:14 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:51:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:51:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 543. Jan 10 04:51:56 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:51:56 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:51:58 hn-dlp platform-python[14457]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:51:58 hn-dlp platform-python[14457]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:51:58 hn-dlp platform-python[14457]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:51:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14457]: new replica keys in LDAP: set() Jan 10 04:51:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14457]: obsolete replica keys in local HSM: set() Jan 10 04:51:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14457]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:51:59 hn-dlp ipa-ods-exporter[14457]: Traceback (most recent call last): Jan 10 04:51:59 hn-dlp ipa-ods-exporter[14457]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:51:59 hn-dlp ipa-ods-exporter[14457]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:51:59 hn-dlp ipa-ods-exporter[14457]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:51:59 hn-dlp ipa-ods-exporter[14457]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:51:59 hn-dlp ipa-ods-exporter[14457]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:51:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:51:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:52:14 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:52:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:52:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 544. Jan 10 04:52:59 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:52:59 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:53:02 hn-dlp platform-python[14465]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:53:02 hn-dlp platform-python[14465]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:53:02 hn-dlp platform-python[14465]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:53:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14465]: new replica keys in LDAP: set() Jan 10 04:53:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14465]: obsolete replica keys in local HSM: set() Jan 10 04:53:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14465]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:53:02 hn-dlp ipa-ods-exporter[14465]: Traceback (most recent call last): Jan 10 04:53:02 hn-dlp ipa-ods-exporter[14465]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:53:02 hn-dlp ipa-ods-exporter[14465]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:53:02 hn-dlp ipa-ods-exporter[14465]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:53:02 hn-dlp ipa-ods-exporter[14465]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:53:02 hn-dlp ipa-ods-exporter[14465]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:53:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:53:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:53:14 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:53:14 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:54:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:54:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 545. Jan 10 04:54:02 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:54:02 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:54:05 hn-dlp platform-python[14475]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:54:05 hn-dlp platform-python[14475]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:54:05 hn-dlp platform-python[14475]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:54:05 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14475]: new replica keys in LDAP: set() Jan 10 04:54:05 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14475]: obsolete replica keys in local HSM: set() Jan 10 04:54:05 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14475]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:54:05 hn-dlp ipa-ods-exporter[14475]: Traceback (most recent call last): Jan 10 04:54:05 hn-dlp ipa-ods-exporter[14475]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:54:05 hn-dlp ipa-ods-exporter[14475]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:54:05 hn-dlp ipa-ods-exporter[14475]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:54:05 hn-dlp ipa-ods-exporter[14475]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:54:05 hn-dlp ipa-ods-exporter[14475]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:54:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:54:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:54:14 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:55:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:55:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 546. Jan 10 04:55:06 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:55:06 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:55:08 hn-dlp platform-python[14484]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:55:08 hn-dlp platform-python[14484]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:55:08 hn-dlp platform-python[14484]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:55:08 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14484]: new replica keys in LDAP: set() Jan 10 04:55:08 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14484]: obsolete replica keys in local HSM: set() Jan 10 04:55:08 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14484]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:55:08 hn-dlp ipa-ods-exporter[14484]: Traceback (most recent call last): Jan 10 04:55:08 hn-dlp ipa-ods-exporter[14484]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:55:08 hn-dlp ipa-ods-exporter[14484]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:55:08 hn-dlp ipa-ods-exporter[14484]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:55:08 hn-dlp ipa-ods-exporter[14484]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:55:08 hn-dlp ipa-ods-exporter[14484]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:55:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:55:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:55:14 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:55:14 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:56:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:56:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 547. Jan 10 04:56:09 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:56:09 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:56:11 hn-dlp platform-python[14493]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:56:11 hn-dlp platform-python[14493]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:56:11 hn-dlp platform-python[14493]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:56:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14493]: new replica keys in LDAP: set() Jan 10 04:56:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14493]: obsolete replica keys in local HSM: set() Jan 10 04:56:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14493]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 04:56:12 hn-dlp ipa-ods-exporter[14493]: Traceback (most recent call last): Jan 10 04:56:12 hn-dlp ipa-ods-exporter[14493]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:56:12 hn-dlp ipa-ods-exporter[14493]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:56:12 hn-dlp ipa-ods-exporter[14493]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:56:12 hn-dlp ipa-ods-exporter[14493]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:56:12 hn-dlp ipa-ods-exporter[14493]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:56:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:56:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:56:14 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:57:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:57:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 548. Jan 10 04:57:12 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:57:12 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:57:14 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:57:14 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:57:15 hn-dlp platform-python[14501]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:57:15 hn-dlp platform-python[14501]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:57:15 hn-dlp platform-python[14501]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:57:15 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14501]: new replica keys in LDAP: set() Jan 10 04:57:15 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14501]: obsolete replica keys in local HSM: set() Jan 10 04:57:15 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14501]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:57:15 hn-dlp ipa-ods-exporter[14501]: Traceback (most recent call last): Jan 10 04:57:15 hn-dlp ipa-ods-exporter[14501]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:57:15 hn-dlp ipa-ods-exporter[14501]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:57:15 hn-dlp ipa-ods-exporter[14501]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:57:15 hn-dlp ipa-ods-exporter[14501]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:57:15 hn-dlp ipa-ods-exporter[14501]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:57:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:57:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:58:14 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 04:58:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:58:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 549. Jan 10 04:58:15 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:58:15 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:58:18 hn-dlp platform-python[14512]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:58:18 hn-dlp platform-python[14512]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:58:18 hn-dlp platform-python[14512]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:58:18 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14512]: new replica keys in LDAP: set() Jan 10 04:58:18 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14512]: obsolete replica keys in local HSM: set() Jan 10 04:58:18 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14512]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 04:58:18 hn-dlp ipa-ods-exporter[14512]: Traceback (most recent call last): Jan 10 04:58:18 hn-dlp ipa-ods-exporter[14512]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:58:18 hn-dlp ipa-ods-exporter[14512]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:58:18 hn-dlp ipa-ods-exporter[14512]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:58:18 hn-dlp ipa-ods-exporter[14512]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:58:18 hn-dlp ipa-ods-exporter[14512]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:58:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:58:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 04:59:14 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 04:59:14 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 04:59:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 04:59:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 550. Jan 10 04:59:19 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 04:59:19 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 04:59:21 hn-dlp platform-python[14521]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 04:59:21 hn-dlp platform-python[14521]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 04:59:21 hn-dlp platform-python[14521]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 04:59:21 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14521]: new replica keys in LDAP: set() Jan 10 04:59:21 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14521]: obsolete replica keys in local HSM: set() Jan 10 04:59:21 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14521]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 04:59:21 hn-dlp ipa-ods-exporter[14521]: Traceback (most recent call last): Jan 10 04:59:21 hn-dlp ipa-ods-exporter[14521]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 04:59:21 hn-dlp ipa-ods-exporter[14521]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 04:59:21 hn-dlp ipa-ods-exporter[14521]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 04:59:21 hn-dlp ipa-ods-exporter[14521]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 04:59:21 hn-dlp ipa-ods-exporter[14521]: KeyError: 'popitem(): dictionary is empty' Jan 10 04:59:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 04:59:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:00:00 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '168.192.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 05:00:00 hn-dlp named-pkcs11[1516]: no valid DS resolving '2.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:01 hn-dlp named-pkcs11[1516]: validating 4.133.168.192.in-addr.arpa/PTR: bad cache hit (168.192.in-addr.arpa/DS) Jan 10 05:00:01 hn-dlp named-pkcs11[1516]: broken trust chain resolving '4.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:01 hn-dlp named-pkcs11[1516]: validating 3.133.168.192.in-addr.arpa/PTR: bad cache hit (168.192.in-addr.arpa/DS) Jan 10 05:00:01 hn-dlp named-pkcs11[1516]: broken trust chain resolving '3.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: validating 104.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '104.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: validating 109.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '109.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: validating 110.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '110.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: validating 113.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '113.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: validating 191.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '191.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: validating 192.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '192.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: validating 203.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '203.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: validating 254.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '254.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 104.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '104.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 171.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '171.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 173.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '173.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 183.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '183.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 204.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '204.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 213.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '213.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 216.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '216.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 217.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '217.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 1.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 5.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '5.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 14.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '14.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 15.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '15.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 1.171.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.171.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 2.171.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '2.171.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 100.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '100.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 103.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '103.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 254.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '254.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 104.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '104.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 107.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '107.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 254.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '254.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 5.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '5.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 11.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '11.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 100.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '100.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: validating 254.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '254.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:00:14 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:00:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:00:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 551. Jan 10 05:00:22 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:00:22 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:00:24 hn-dlp platform-python[14534]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:00:24 hn-dlp platform-python[14534]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:00:24 hn-dlp platform-python[14534]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:00:24 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14534]: new replica keys in LDAP: set() Jan 10 05:00:24 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14534]: obsolete replica keys in local HSM: set() Jan 10 05:00:24 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14534]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:00:24 hn-dlp ipa-ods-exporter[14534]: Traceback (most recent call last): Jan 10 05:00:24 hn-dlp ipa-ods-exporter[14534]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:00:24 hn-dlp ipa-ods-exporter[14534]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:00:24 hn-dlp ipa-ods-exporter[14534]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:00:24 hn-dlp ipa-ods-exporter[14534]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:00:24 hn-dlp ipa-ods-exporter[14534]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:00:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:00:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:00:32 hn-dlp systemd[1]: Created slice User Slice of UID 2002. Jan 10 05:00:32 hn-dlp systemd[1]: Started /run/user/2002 mount wrapper. Jan 10 05:00:32 hn-dlp systemd[1]: Starting User Manager for UID 2002... Jan 10 05:00:32 hn-dlp systemd[1]: Started Session 42 of user svcforeman. Jan 10 05:00:32 hn-dlp systemd-logind[736]: New session 42 of user svcforeman. Jan 10 05:00:32 hn-dlp systemd[14549]: Starting D-Bus User Message Bus Socket. Jan 10 05:00:32 hn-dlp systemd[14549]: Started Mark boot as successful after the user session has run 2 minutes. Jan 10 05:00:32 hn-dlp systemd[14549]: Reached target Timers. Jan 10 05:00:32 hn-dlp systemd[14549]: Reached target Paths. Jan 10 05:00:32 hn-dlp systemd[14549]: Listening on D-Bus User Message Bus Socket. Jan 10 05:00:32 hn-dlp systemd[14549]: Reached target Sockets. Jan 10 05:00:32 hn-dlp systemd[14549]: Reached target Basic System. Jan 10 05:00:32 hn-dlp systemd[14549]: Reached target Default. Jan 10 05:00:32 hn-dlp systemd[14549]: Startup finished in 53ms. Jan 10 05:00:32 hn-dlp systemd[1]: Started User Manager for UID 2002. Jan 10 05:00:35 hn-dlp platform-python[14711]: ansible-setup Invoked with gather_timeout=10 gather_subset=['all'] filter=* fact_path=/etc/ansible/facts.d Jan 10 05:01:04 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.131' (uid=0 pid=669 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 05:01:04 hn-dlp dbus-daemon[14828]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 05:01:05 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 05:01:05 hn-dlp setroubleshoot[14828]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der Jan 10 05:01:06 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.1024' (uid=995 pid=14828 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 05:01:06 hn-dlp dbus-daemon[14840]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 05:01:06 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 05:01:08 hn-dlp setroubleshoot[14828]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 05:01:08 hn-dlp setroubleshoot[14828]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-050000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 05:01:14 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:01:14 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:01:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:01:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 552. Jan 10 05:01:25 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:01:25 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:01:29 hn-dlp platform-python[14845]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:01:30 hn-dlp platform-python[14845]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:01:30 hn-dlp platform-python[14845]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:01:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14845]: new replica keys in LDAP: set() Jan 10 05:01:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14845]: obsolete replica keys in local HSM: set() Jan 10 05:01:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14845]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 05:01:30 hn-dlp ipa-ods-exporter[14845]: Traceback (most recent call last): Jan 10 05:01:30 hn-dlp ipa-ods-exporter[14845]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:01:30 hn-dlp ipa-ods-exporter[14845]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:01:30 hn-dlp ipa-ods-exporter[14845]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:01:30 hn-dlp ipa-ods-exporter[14845]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:01:30 hn-dlp ipa-ods-exporter[14845]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:01:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:01:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:01:38 hn-dlp systemd-logind[736]: Session 42 logged out. Waiting for processes to exit. Jan 10 05:01:38 hn-dlp systemd[1]: session-42.scope: Succeeded. Jan 10 05:01:38 hn-dlp systemd-logind[736]: Removed session 42. Jan 10 05:01:38 hn-dlp systemd[1]: Stopping User Manager for UID 2002... Jan 10 05:01:38 hn-dlp systemd[14549]: Stopped target Default. Jan 10 05:01:38 hn-dlp systemd[14549]: Stopped target Basic System. Jan 10 05:01:38 hn-dlp systemd[14549]: Stopped target Paths. Jan 10 05:01:38 hn-dlp systemd[14549]: Stopped target Timers. Jan 10 05:01:38 hn-dlp systemd[14549]: grub-boot-success.timer: Succeeded. Jan 10 05:01:38 hn-dlp systemd[14549]: Stopped Mark boot as successful after the user session has run 2 minutes. Jan 10 05:01:38 hn-dlp systemd[14549]: Stopped target Sockets. Jan 10 05:01:38 hn-dlp systemd[14549]: dbus.socket: Succeeded. Jan 10 05:01:38 hn-dlp systemd[14549]: Closed D-Bus User Message Bus Socket. Jan 10 05:01:38 hn-dlp systemd[14549]: Reached target Shutdown. Jan 10 05:01:38 hn-dlp systemd[14549]: Starting Exit the Session... Jan 10 05:01:38 hn-dlp systemd[1]: user@2002.service: Succeeded. Jan 10 05:01:38 hn-dlp systemd[1]: Stopped User Manager for UID 2002. Jan 10 05:01:38 hn-dlp systemd[1]: Stopping /run/user/2002 mount wrapper... Jan 10 05:01:38 hn-dlp systemd[1]: Removed slice User Slice of UID 2002. Jan 10 05:01:38 hn-dlp systemd[1]: run-user-2002.mount: Succeeded. Jan 10 05:01:38 hn-dlp systemd[1]: user-runtime-dir@2002.service: Succeeded. Jan 10 05:01:38 hn-dlp systemd[1]: Stopped /run/user/2002 mount wrapper. Jan 10 05:02:12 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.131' (uid=0 pid=669 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 05:02:12 hn-dlp dbus-daemon[14864]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 05:02:13 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 05:02:14 hn-dlp setroubleshoot[14864]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der Jan 10 05:02:14 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.1031' (uid=995 pid=14864 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 05:02:14 hn-dlp dbus-daemon[14876]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 05:02:14 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 05:02:14 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:02:16 hn-dlp setroubleshoot[14864]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 05:02:16 hn-dlp setroubleshoot[14864]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-050000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 05:02:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:02:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 553. Jan 10 05:02:30 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:02:30 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:02:33 hn-dlp platform-python[14880]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:02:33 hn-dlp platform-python[14880]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:02:33 hn-dlp platform-python[14880]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:02:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14880]: new replica keys in LDAP: set() Jan 10 05:02:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14880]: obsolete replica keys in local HSM: set() Jan 10 05:02:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14880]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:02:34 hn-dlp ipa-ods-exporter[14880]: Traceback (most recent call last): Jan 10 05:02:34 hn-dlp ipa-ods-exporter[14880]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:02:34 hn-dlp ipa-ods-exporter[14880]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:02:34 hn-dlp ipa-ods-exporter[14880]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:02:34 hn-dlp ipa-ods-exporter[14880]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:02:34 hn-dlp ipa-ods-exporter[14880]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:02:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:02:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:03:15 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 05:03:15 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:03:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:03:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 554. Jan 10 05:03:34 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:03:34 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:03:36 hn-dlp platform-python[14891]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:03:36 hn-dlp platform-python[14891]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:03:36 hn-dlp platform-python[14891]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:03:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14891]: new replica keys in LDAP: set() Jan 10 05:03:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14891]: obsolete replica keys in local HSM: set() Jan 10 05:03:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14891]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:03:37 hn-dlp ipa-ods-exporter[14891]: Traceback (most recent call last): Jan 10 05:03:37 hn-dlp ipa-ods-exporter[14891]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:03:37 hn-dlp ipa-ods-exporter[14891]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:03:37 hn-dlp ipa-ods-exporter[14891]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:03:37 hn-dlp ipa-ods-exporter[14891]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:03:37 hn-dlp ipa-ods-exporter[14891]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:03:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:03:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:04:15 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:04:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:04:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 555. Jan 10 05:04:37 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:04:37 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:04:40 hn-dlp platform-python[14900]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:04:40 hn-dlp platform-python[14900]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:04:40 hn-dlp platform-python[14900]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:04:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14900]: new replica keys in LDAP: set() Jan 10 05:04:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14900]: obsolete replica keys in local HSM: set() Jan 10 05:04:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14900]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:04:40 hn-dlp ipa-ods-exporter[14900]: Traceback (most recent call last): Jan 10 05:04:40 hn-dlp ipa-ods-exporter[14900]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:04:40 hn-dlp ipa-ods-exporter[14900]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:04:40 hn-dlp ipa-ods-exporter[14900]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:04:40 hn-dlp ipa-ods-exporter[14900]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:04:40 hn-dlp ipa-ods-exporter[14900]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:04:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:04:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:05:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:05:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:05:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:05:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 556. Jan 10 05:05:40 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:05:40 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:05:43 hn-dlp platform-python[14912]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:05:43 hn-dlp platform-python[14912]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:05:43 hn-dlp platform-python[14912]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:05:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14912]: new replica keys in LDAP: set() Jan 10 05:05:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14912]: obsolete replica keys in local HSM: set() Jan 10 05:05:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14912]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:05:43 hn-dlp ipa-ods-exporter[14912]: Traceback (most recent call last): Jan 10 05:05:43 hn-dlp ipa-ods-exporter[14912]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:05:43 hn-dlp ipa-ods-exporter[14912]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:05:43 hn-dlp ipa-ods-exporter[14912]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:05:43 hn-dlp ipa-ods-exporter[14912]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:05:43 hn-dlp ipa-ods-exporter[14912]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:05:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:05:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:06:16 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:06:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:06:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 557. Jan 10 05:06:43 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:06:43 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:06:46 hn-dlp platform-python[14920]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:06:46 hn-dlp platform-python[14920]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:06:46 hn-dlp platform-python[14920]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:06:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14920]: new replica keys in LDAP: set() Jan 10 05:06:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14920]: obsolete replica keys in local HSM: set() Jan 10 05:06:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14920]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:06:46 hn-dlp ipa-ods-exporter[14920]: Traceback (most recent call last): Jan 10 05:06:46 hn-dlp ipa-ods-exporter[14920]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:06:46 hn-dlp ipa-ods-exporter[14920]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:06:46 hn-dlp ipa-ods-exporter[14920]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:06:46 hn-dlp ipa-ods-exporter[14920]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:06:46 hn-dlp ipa-ods-exporter[14920]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:06:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:06:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:07:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:07:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:07:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:07:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 558. Jan 10 05:07:47 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:07:47 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:07:49 hn-dlp platform-python[14928]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:07:49 hn-dlp platform-python[14928]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:07:49 hn-dlp platform-python[14928]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:07:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14928]: new replica keys in LDAP: set() Jan 10 05:07:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14928]: obsolete replica keys in local HSM: set() Jan 10 05:07:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14928]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 05:07:49 hn-dlp ipa-ods-exporter[14928]: Traceback (most recent call last): Jan 10 05:07:49 hn-dlp ipa-ods-exporter[14928]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:07:49 hn-dlp ipa-ods-exporter[14928]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:07:49 hn-dlp ipa-ods-exporter[14928]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:07:49 hn-dlp ipa-ods-exporter[14928]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:07:49 hn-dlp ipa-ods-exporter[14928]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:07:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:07:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:08:16 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:08:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:08:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 559. Jan 10 05:08:50 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:08:50 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:08:53 hn-dlp platform-python[14939]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:08:53 hn-dlp platform-python[14939]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:08:53 hn-dlp platform-python[14939]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:08:53 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14939]: new replica keys in LDAP: set() Jan 10 05:08:53 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14939]: obsolete replica keys in local HSM: set() Jan 10 05:08:53 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14939]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:08:53 hn-dlp ipa-ods-exporter[14939]: Traceback (most recent call last): Jan 10 05:08:53 hn-dlp ipa-ods-exporter[14939]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:08:53 hn-dlp ipa-ods-exporter[14939]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:08:53 hn-dlp ipa-ods-exporter[14939]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:08:53 hn-dlp ipa-ods-exporter[14939]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:08:53 hn-dlp ipa-ods-exporter[14939]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:08:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:08:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:09:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:09:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:09:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:09:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 560. Jan 10 05:09:53 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:09:53 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:09:56 hn-dlp platform-python[14949]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:09:56 hn-dlp platform-python[14949]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:09:56 hn-dlp platform-python[14949]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:09:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14949]: new replica keys in LDAP: set() Jan 10 05:09:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14949]: obsolete replica keys in local HSM: set() Jan 10 05:09:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14949]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:09:56 hn-dlp ipa-ods-exporter[14949]: Traceback (most recent call last): Jan 10 05:09:56 hn-dlp ipa-ods-exporter[14949]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:09:56 hn-dlp ipa-ods-exporter[14949]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:09:56 hn-dlp ipa-ods-exporter[14949]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:09:56 hn-dlp ipa-ods-exporter[14949]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:09:56 hn-dlp ipa-ods-exporter[14949]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:09:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:09:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:10:16 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:10:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:10:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 561. Jan 10 05:10:57 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:10:57 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:10:59 hn-dlp platform-python[14958]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:10:59 hn-dlp platform-python[14958]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:10:59 hn-dlp platform-python[14958]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:10:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14958]: new replica keys in LDAP: set() Jan 10 05:10:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14958]: obsolete replica keys in local HSM: set() Jan 10 05:10:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14958]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 05:10:59 hn-dlp ipa-ods-exporter[14958]: Traceback (most recent call last): Jan 10 05:10:59 hn-dlp ipa-ods-exporter[14958]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:10:59 hn-dlp ipa-ods-exporter[14958]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:10:59 hn-dlp ipa-ods-exporter[14958]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:10:59 hn-dlp ipa-ods-exporter[14958]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:10:59 hn-dlp ipa-ods-exporter[14958]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:11:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:11:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:11:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:11:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:12:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:12:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 562. Jan 10 05:12:00 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:12:00 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:12:02 hn-dlp platform-python[14968]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:12:02 hn-dlp platform-python[14968]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:12:02 hn-dlp platform-python[14968]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:12:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14968]: new replica keys in LDAP: set() Jan 10 05:12:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14968]: obsolete replica keys in local HSM: set() Jan 10 05:12:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14968]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:12:03 hn-dlp ipa-ods-exporter[14968]: Traceback (most recent call last): Jan 10 05:12:03 hn-dlp ipa-ods-exporter[14968]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:12:03 hn-dlp ipa-ods-exporter[14968]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:12:03 hn-dlp ipa-ods-exporter[14968]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:12:03 hn-dlp ipa-ods-exporter[14968]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:12:03 hn-dlp ipa-ods-exporter[14968]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:12:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:12:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:12:16 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:13:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:13:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 563. Jan 10 05:13:03 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:13:03 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:13:06 hn-dlp platform-python[14977]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:13:06 hn-dlp platform-python[14977]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:13:06 hn-dlp platform-python[14977]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:13:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14977]: new replica keys in LDAP: set() Jan 10 05:13:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14977]: obsolete replica keys in local HSM: set() Jan 10 05:13:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14977]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 05:13:06 hn-dlp ipa-ods-exporter[14977]: Traceback (most recent call last): Jan 10 05:13:06 hn-dlp ipa-ods-exporter[14977]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:13:06 hn-dlp ipa-ods-exporter[14977]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:13:06 hn-dlp ipa-ods-exporter[14977]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:13:06 hn-dlp ipa-ods-exporter[14977]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:13:06 hn-dlp ipa-ods-exporter[14977]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:13:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:13:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:13:15 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 05:13:15 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:14:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:14:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 564. Jan 10 05:14:06 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:14:06 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:14:09 hn-dlp platform-python[14986]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:14:09 hn-dlp platform-python[14986]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:14:09 hn-dlp platform-python[14986]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:14:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14986]: new replica keys in LDAP: set() Jan 10 05:14:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14986]: obsolete replica keys in local HSM: set() Jan 10 05:14:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14986]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:14:09 hn-dlp ipa-ods-exporter[14986]: Traceback (most recent call last): Jan 10 05:14:09 hn-dlp ipa-ods-exporter[14986]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:14:09 hn-dlp ipa-ods-exporter[14986]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:14:09 hn-dlp ipa-ods-exporter[14986]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:14:09 hn-dlp ipa-ods-exporter[14986]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:14:09 hn-dlp ipa-ods-exporter[14986]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:14:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:14:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:14:16 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:15:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:15:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 565. Jan 10 05:15:10 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:15:10 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:15:12 hn-dlp platform-python[14995]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:15:12 hn-dlp platform-python[14995]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:15:12 hn-dlp platform-python[14995]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:15:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14995]: new replica keys in LDAP: set() Jan 10 05:15:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14995]: obsolete replica keys in local HSM: set() Jan 10 05:15:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[14995]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 05:15:12 hn-dlp ipa-ods-exporter[14995]: Traceback (most recent call last): Jan 10 05:15:12 hn-dlp ipa-ods-exporter[14995]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:15:12 hn-dlp ipa-ods-exporter[14995]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:15:12 hn-dlp ipa-ods-exporter[14995]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:15:12 hn-dlp ipa-ods-exporter[14995]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:15:12 hn-dlp ipa-ods-exporter[14995]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:15:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:15:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:15:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:15:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:16:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:16:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 566. Jan 10 05:16:13 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:16:13 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:16:15 hn-dlp platform-python[15005]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:16:15 hn-dlp platform-python[15005]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:16:15 hn-dlp platform-python[15005]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:16:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15005]: new replica keys in LDAP: set() Jan 10 05:16:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15005]: obsolete replica keys in local HSM: set() Jan 10 05:16:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15005]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:16:16 hn-dlp ipa-ods-exporter[15005]: Traceback (most recent call last): Jan 10 05:16:16 hn-dlp ipa-ods-exporter[15005]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:16:16 hn-dlp ipa-ods-exporter[15005]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:16:16 hn-dlp ipa-ods-exporter[15005]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:16:16 hn-dlp ipa-ods-exporter[15005]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:16:16 hn-dlp ipa-ods-exporter[15005]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:16:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:16:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:16:16 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:17:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:17:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:17:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:17:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 567. Jan 10 05:17:16 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:17:16 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:17:19 hn-dlp platform-python[15013]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:17:19 hn-dlp platform-python[15013]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:17:19 hn-dlp platform-python[15013]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:17:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15013]: new replica keys in LDAP: set() Jan 10 05:17:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15013]: obsolete replica keys in local HSM: set() Jan 10 05:17:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15013]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:17:19 hn-dlp ipa-ods-exporter[15013]: Traceback (most recent call last): Jan 10 05:17:19 hn-dlp ipa-ods-exporter[15013]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:17:19 hn-dlp ipa-ods-exporter[15013]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:17:19 hn-dlp ipa-ods-exporter[15013]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:17:19 hn-dlp ipa-ods-exporter[15013]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:17:19 hn-dlp ipa-ods-exporter[15013]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:17:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:17:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:18:16 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:18:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:18:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 568. Jan 10 05:18:19 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:18:19 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:18:22 hn-dlp platform-python[15023]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:18:22 hn-dlp platform-python[15023]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:18:22 hn-dlp platform-python[15023]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:18:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15023]: new replica keys in LDAP: set() Jan 10 05:18:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15023]: obsolete replica keys in local HSM: set() Jan 10 05:18:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15023]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:18:22 hn-dlp ipa-ods-exporter[15023]: Traceback (most recent call last): Jan 10 05:18:22 hn-dlp ipa-ods-exporter[15023]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:18:22 hn-dlp ipa-ods-exporter[15023]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:18:22 hn-dlp ipa-ods-exporter[15023]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:18:22 hn-dlp ipa-ods-exporter[15023]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:18:22 hn-dlp ipa-ods-exporter[15023]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:18:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:18:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:19:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:19:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:19:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:19:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 569. Jan 10 05:19:23 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:19:23 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:19:25 hn-dlp platform-python[15036]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:19:25 hn-dlp platform-python[15036]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:19:25 hn-dlp platform-python[15036]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:19:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15036]: new replica keys in LDAP: set() Jan 10 05:19:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15036]: obsolete replica keys in local HSM: set() Jan 10 05:19:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15036]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:19:25 hn-dlp ipa-ods-exporter[15036]: Traceback (most recent call last): Jan 10 05:19:25 hn-dlp ipa-ods-exporter[15036]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:19:25 hn-dlp ipa-ods-exporter[15036]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:19:25 hn-dlp ipa-ods-exporter[15036]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:19:25 hn-dlp ipa-ods-exporter[15036]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:19:25 hn-dlp ipa-ods-exporter[15036]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:19:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:19:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:20:16 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:20:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:20:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 570. Jan 10 05:20:26 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:20:26 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:20:28 hn-dlp platform-python[15047]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:20:28 hn-dlp platform-python[15047]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:20:28 hn-dlp platform-python[15047]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:20:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15047]: new replica keys in LDAP: set() Jan 10 05:20:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15047]: obsolete replica keys in local HSM: set() Jan 10 05:20:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15047]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:20:29 hn-dlp ipa-ods-exporter[15047]: Traceback (most recent call last): Jan 10 05:20:29 hn-dlp ipa-ods-exporter[15047]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:20:29 hn-dlp ipa-ods-exporter[15047]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:20:29 hn-dlp ipa-ods-exporter[15047]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:20:29 hn-dlp ipa-ods-exporter[15047]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:20:29 hn-dlp ipa-ods-exporter[15047]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:20:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:20:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:21:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:21:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:21:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:21:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 571. Jan 10 05:21:29 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:21:29 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:21:32 hn-dlp platform-python[15056]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:21:32 hn-dlp platform-python[15056]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:21:32 hn-dlp platform-python[15056]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:21:32 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15056]: new replica keys in LDAP: set() Jan 10 05:21:32 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15056]: obsolete replica keys in local HSM: set() Jan 10 05:21:32 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15056]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:21:32 hn-dlp ipa-ods-exporter[15056]: Traceback (most recent call last): Jan 10 05:21:32 hn-dlp ipa-ods-exporter[15056]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:21:32 hn-dlp ipa-ods-exporter[15056]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:21:32 hn-dlp ipa-ods-exporter[15056]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:21:32 hn-dlp ipa-ods-exporter[15056]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:21:32 hn-dlp ipa-ods-exporter[15056]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:21:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:21:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:22:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:22:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:22:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 572. Jan 10 05:22:32 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:22:32 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:22:35 hn-dlp platform-python[15065]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:22:35 hn-dlp platform-python[15065]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:22:35 hn-dlp platform-python[15065]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:22:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15065]: new replica keys in LDAP: set() Jan 10 05:22:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15065]: obsolete replica keys in local HSM: set() Jan 10 05:22:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15065]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:22:35 hn-dlp ipa-ods-exporter[15065]: Traceback (most recent call last): Jan 10 05:22:35 hn-dlp ipa-ods-exporter[15065]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:22:35 hn-dlp ipa-ods-exporter[15065]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:22:35 hn-dlp ipa-ods-exporter[15065]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:22:35 hn-dlp ipa-ods-exporter[15065]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:22:35 hn-dlp ipa-ods-exporter[15065]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:22:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:22:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:23:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:23:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:23:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:23:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 573. Jan 10 05:23:35 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:23:35 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:23:38 hn-dlp platform-python[15074]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:23:38 hn-dlp platform-python[15074]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:23:38 hn-dlp platform-python[15074]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:23:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15074]: new replica keys in LDAP: set() Jan 10 05:23:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15074]: obsolete replica keys in local HSM: set() Jan 10 05:23:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15074]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:23:38 hn-dlp ipa-ods-exporter[15074]: Traceback (most recent call last): Jan 10 05:23:38 hn-dlp ipa-ods-exporter[15074]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:23:38 hn-dlp ipa-ods-exporter[15074]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:23:38 hn-dlp ipa-ods-exporter[15074]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:23:38 hn-dlp ipa-ods-exporter[15074]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:23:38 hn-dlp ipa-ods-exporter[15074]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:23:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:23:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:24:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:24:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:24:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 574. Jan 10 05:24:39 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:24:39 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:24:41 hn-dlp platform-python[15085]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:24:41 hn-dlp platform-python[15085]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:24:41 hn-dlp platform-python[15085]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:24:41 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15085]: new replica keys in LDAP: set() Jan 10 05:24:41 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15085]: obsolete replica keys in local HSM: set() Jan 10 05:24:41 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15085]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 05:24:41 hn-dlp ipa-ods-exporter[15085]: Traceback (most recent call last): Jan 10 05:24:41 hn-dlp ipa-ods-exporter[15085]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:24:41 hn-dlp ipa-ods-exporter[15085]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:24:41 hn-dlp ipa-ods-exporter[15085]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:24:41 hn-dlp ipa-ods-exporter[15085]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:24:41 hn-dlp ipa-ods-exporter[15085]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:24:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:24:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:25:15 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 05:25:15 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:25:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:25:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 575. Jan 10 05:25:42 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:25:42 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:25:44 hn-dlp platform-python[15095]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:25:44 hn-dlp platform-python[15095]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:25:44 hn-dlp platform-python[15095]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:25:45 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15095]: new replica keys in LDAP: set() Jan 10 05:25:45 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15095]: obsolete replica keys in local HSM: set() Jan 10 05:25:45 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15095]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:25:45 hn-dlp ipa-ods-exporter[15095]: Traceback (most recent call last): Jan 10 05:25:45 hn-dlp ipa-ods-exporter[15095]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:25:45 hn-dlp ipa-ods-exporter[15095]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:25:45 hn-dlp ipa-ods-exporter[15095]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:25:45 hn-dlp ipa-ods-exporter[15095]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:25:45 hn-dlp ipa-ods-exporter[15095]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:25:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:25:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:26:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:26:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:26:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 576. Jan 10 05:26:45 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:26:45 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:26:48 hn-dlp platform-python[15103]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:26:48 hn-dlp platform-python[15103]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:26:48 hn-dlp platform-python[15103]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:26:48 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15103]: new replica keys in LDAP: set() Jan 10 05:26:48 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15103]: obsolete replica keys in local HSM: set() Jan 10 05:26:48 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15103]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 05:26:48 hn-dlp ipa-ods-exporter[15103]: Traceback (most recent call last): Jan 10 05:26:48 hn-dlp ipa-ods-exporter[15103]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:26:48 hn-dlp ipa-ods-exporter[15103]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:26:48 hn-dlp ipa-ods-exporter[15103]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:26:48 hn-dlp ipa-ods-exporter[15103]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:26:48 hn-dlp ipa-ods-exporter[15103]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:26:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:26:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:27:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:27:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:27:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:27:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 577. Jan 10 05:27:49 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:27:49 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:27:51 hn-dlp platform-python[15113]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:27:51 hn-dlp platform-python[15113]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:27:51 hn-dlp platform-python[15113]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:27:51 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15113]: new replica keys in LDAP: set() Jan 10 05:27:51 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15113]: obsolete replica keys in local HSM: set() Jan 10 05:27:51 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15113]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:27:51 hn-dlp ipa-ods-exporter[15113]: Traceback (most recent call last): Jan 10 05:27:51 hn-dlp ipa-ods-exporter[15113]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:27:51 hn-dlp ipa-ods-exporter[15113]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:27:51 hn-dlp ipa-ods-exporter[15113]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:27:51 hn-dlp ipa-ods-exporter[15113]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:27:51 hn-dlp ipa-ods-exporter[15113]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:27:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:27:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:28:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:28:44 hn-dlp systemd[1]: Starting dnf makecache... Jan 10 05:28:47 hn-dlp dnf[15120]: Updating Subscription Management repositories. Jan 10 05:28:48 hn-dlp dnf[15120]: Metadata cache refreshed recently. Jan 10 05:28:48 hn-dlp systemd[1]: dnf-makecache.service: Succeeded. Jan 10 05:28:48 hn-dlp systemd[1]: Started dnf makecache. Jan 10 05:28:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:28:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 578. Jan 10 05:28:52 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:28:52 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:28:54 hn-dlp platform-python[15126]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:28:54 hn-dlp platform-python[15126]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:28:54 hn-dlp platform-python[15126]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:28:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15126]: new replica keys in LDAP: set() Jan 10 05:28:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15126]: obsolete replica keys in local HSM: set() Jan 10 05:28:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15126]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:28:55 hn-dlp ipa-ods-exporter[15126]: Traceback (most recent call last): Jan 10 05:28:55 hn-dlp ipa-ods-exporter[15126]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:28:55 hn-dlp ipa-ods-exporter[15126]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:28:55 hn-dlp ipa-ods-exporter[15126]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:28:55 hn-dlp ipa-ods-exporter[15126]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:28:55 hn-dlp ipa-ods-exporter[15126]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:28:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:28:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:29:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:29:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:29:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:29:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 579. Jan 10 05:29:55 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:29:55 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:29:58 hn-dlp platform-python[15137]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:29:58 hn-dlp platform-python[15137]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:29:58 hn-dlp platform-python[15137]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:29:58 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15137]: new replica keys in LDAP: set() Jan 10 05:29:58 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15137]: obsolete replica keys in local HSM: set() Jan 10 05:29:58 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15137]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:29:58 hn-dlp ipa-ods-exporter[15137]: Traceback (most recent call last): Jan 10 05:29:58 hn-dlp ipa-ods-exporter[15137]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:29:58 hn-dlp ipa-ods-exporter[15137]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:29:58 hn-dlp ipa-ods-exporter[15137]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:29:58 hn-dlp ipa-ods-exporter[15137]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:29:58 hn-dlp ipa-ods-exporter[15137]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:29:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:29:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:30:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:30:34 hn-dlp systemd[1]: Created slice User Slice of UID 2002. Jan 10 05:30:34 hn-dlp systemd[1]: Started /run/user/2002 mount wrapper. Jan 10 05:30:34 hn-dlp systemd[1]: Starting User Manager for UID 2002... Jan 10 05:30:34 hn-dlp systemd-logind[736]: New session 44 of user svcforeman. Jan 10 05:30:34 hn-dlp systemd[1]: Started Session 44 of user svcforeman. Jan 10 05:30:34 hn-dlp systemd[15150]: Starting D-Bus User Message Bus Socket. Jan 10 05:30:34 hn-dlp systemd[15150]: Started Mark boot as successful after the user session has run 2 minutes. Jan 10 05:30:34 hn-dlp systemd[15150]: Reached target Timers. Jan 10 05:30:34 hn-dlp systemd[15150]: Reached target Paths. Jan 10 05:30:34 hn-dlp systemd[15150]: Listening on D-Bus User Message Bus Socket. Jan 10 05:30:34 hn-dlp systemd[15150]: Reached target Sockets. Jan 10 05:30:34 hn-dlp systemd[15150]: Reached target Basic System. Jan 10 05:30:34 hn-dlp systemd[15150]: Reached target Default. Jan 10 05:30:34 hn-dlp systemd[15150]: Startup finished in 109ms. Jan 10 05:30:34 hn-dlp systemd[1]: Started User Manager for UID 2002. Jan 10 05:30:37 hn-dlp platform-python[15313]: ansible-setup Invoked with gather_timeout=10 gather_subset=['all'] filter=* fact_path=/etc/ansible/facts.d Jan 10 05:30:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:30:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 580. Jan 10 05:30:58 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:30:58 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:31:01 hn-dlp platform-python[15419]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:31:01 hn-dlp platform-python[15419]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:31:01 hn-dlp platform-python[15419]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:31:01 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15419]: new replica keys in LDAP: set() Jan 10 05:31:01 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15419]: obsolete replica keys in local HSM: set() Jan 10 05:31:01 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15419]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:31:01 hn-dlp ipa-ods-exporter[15419]: Traceback (most recent call last): Jan 10 05:31:01 hn-dlp ipa-ods-exporter[15419]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:31:01 hn-dlp ipa-ods-exporter[15419]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:31:01 hn-dlp ipa-ods-exporter[15419]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:31:01 hn-dlp ipa-ods-exporter[15419]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:31:01 hn-dlp ipa-ods-exporter[15419]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:31:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:31:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:31:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:31:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:31:42 hn-dlp systemd[1]: session-44.scope: Succeeded. Jan 10 05:31:42 hn-dlp systemd-logind[736]: Session 44 logged out. Waiting for processes to exit. Jan 10 05:31:42 hn-dlp systemd-logind[736]: Removed session 44. Jan 10 05:31:42 hn-dlp systemd[1]: Stopping User Manager for UID 2002... Jan 10 05:31:42 hn-dlp systemd[15150]: Stopped target Default. Jan 10 05:31:42 hn-dlp systemd[15150]: Stopped target Basic System. Jan 10 05:31:42 hn-dlp systemd[15150]: Stopped target Timers. Jan 10 05:31:42 hn-dlp systemd[15150]: grub-boot-success.timer: Succeeded. Jan 10 05:31:42 hn-dlp systemd[15150]: Stopped Mark boot as successful after the user session has run 2 minutes. Jan 10 05:31:42 hn-dlp systemd[15150]: Stopped target Paths. Jan 10 05:31:42 hn-dlp systemd[15150]: Stopped target Sockets. Jan 10 05:31:42 hn-dlp systemd[15150]: dbus.socket: Succeeded. Jan 10 05:31:42 hn-dlp systemd[15150]: Closed D-Bus User Message Bus Socket. Jan 10 05:31:42 hn-dlp systemd[15150]: Reached target Shutdown. Jan 10 05:31:42 hn-dlp systemd[15150]: Starting Exit the Session... Jan 10 05:31:42 hn-dlp systemd[1]: user@2002.service: Succeeded. Jan 10 05:31:42 hn-dlp systemd[1]: Stopped User Manager for UID 2002. Jan 10 05:31:42 hn-dlp systemd[1]: Stopping /run/user/2002 mount wrapper... Jan 10 05:31:42 hn-dlp systemd[1]: Removed slice User Slice of UID 2002. Jan 10 05:31:42 hn-dlp systemd[1]: run-user-2002.mount: Succeeded. Jan 10 05:31:42 hn-dlp systemd[1]: user-runtime-dir@2002.service: Succeeded. Jan 10 05:31:42 hn-dlp systemd[1]: Stopped /run/user/2002 mount wrapper. Jan 10 05:32:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:32:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 581. Jan 10 05:32:02 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:32:02 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:32:04 hn-dlp platform-python[15440]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:32:04 hn-dlp platform-python[15440]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:32:04 hn-dlp platform-python[15440]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:32:04 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15440]: new replica keys in LDAP: set() Jan 10 05:32:04 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15440]: obsolete replica keys in local HSM: set() Jan 10 05:32:04 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15440]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:32:04 hn-dlp ipa-ods-exporter[15440]: Traceback (most recent call last): Jan 10 05:32:04 hn-dlp ipa-ods-exporter[15440]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:32:04 hn-dlp ipa-ods-exporter[15440]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:32:04 hn-dlp ipa-ods-exporter[15440]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:32:04 hn-dlp ipa-ods-exporter[15440]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:32:04 hn-dlp ipa-ods-exporter[15440]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:32:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:32:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:32:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:33:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:33:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 582. Jan 10 05:33:05 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:33:05 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:33:07 hn-dlp platform-python[15449]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:33:07 hn-dlp platform-python[15449]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:33:07 hn-dlp platform-python[15449]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:33:08 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15449]: new replica keys in LDAP: set() Jan 10 05:33:08 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15449]: obsolete replica keys in local HSM: set() Jan 10 05:33:08 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15449]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:33:08 hn-dlp ipa-ods-exporter[15449]: Traceback (most recent call last): Jan 10 05:33:08 hn-dlp ipa-ods-exporter[15449]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:33:08 hn-dlp ipa-ods-exporter[15449]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:33:08 hn-dlp ipa-ods-exporter[15449]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:33:08 hn-dlp ipa-ods-exporter[15449]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:33:08 hn-dlp ipa-ods-exporter[15449]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:33:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:33:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:33:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:33:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:34:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:34:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 583. Jan 10 05:34:08 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:34:08 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:34:10 hn-dlp platform-python[15459]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:34:10 hn-dlp platform-python[15459]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:34:10 hn-dlp platform-python[15459]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:34:11 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15459]: new replica keys in LDAP: set() Jan 10 05:34:11 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15459]: obsolete replica keys in local HSM: set() Jan 10 05:34:11 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15459]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 05:34:11 hn-dlp ipa-ods-exporter[15459]: Traceback (most recent call last): Jan 10 05:34:11 hn-dlp ipa-ods-exporter[15459]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:34:11 hn-dlp ipa-ods-exporter[15459]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:34:11 hn-dlp ipa-ods-exporter[15459]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:34:11 hn-dlp ipa-ods-exporter[15459]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:34:11 hn-dlp ipa-ods-exporter[15459]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:34:11 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:34:11 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:34:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:35:11 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:35:11 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 584. Jan 10 05:35:11 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:35:11 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:35:13 hn-dlp platform-python[15467]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:35:13 hn-dlp platform-python[15467]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:35:13 hn-dlp platform-python[15467]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:35:14 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15467]: new replica keys in LDAP: set() Jan 10 05:35:14 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15467]: obsolete replica keys in local HSM: set() Jan 10 05:35:14 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15467]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:35:14 hn-dlp ipa-ods-exporter[15467]: Traceback (most recent call last): Jan 10 05:35:14 hn-dlp ipa-ods-exporter[15467]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:35:14 hn-dlp ipa-ods-exporter[15467]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:35:14 hn-dlp ipa-ods-exporter[15467]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:35:14 hn-dlp ipa-ods-exporter[15467]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:35:14 hn-dlp ipa-ods-exporter[15467]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:35:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:35:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:35:15 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 05:35:15 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:36:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:36:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 585. Jan 10 05:36:14 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:36:14 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:36:17 hn-dlp platform-python[15478]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:36:17 hn-dlp platform-python[15478]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:36:17 hn-dlp platform-python[15478]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:36:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:36:17 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15478]: new replica keys in LDAP: set() Jan 10 05:36:17 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15478]: obsolete replica keys in local HSM: set() Jan 10 05:36:17 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15478]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:36:17 hn-dlp ipa-ods-exporter[15478]: Traceback (most recent call last): Jan 10 05:36:17 hn-dlp ipa-ods-exporter[15478]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:36:17 hn-dlp ipa-ods-exporter[15478]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:36:17 hn-dlp ipa-ods-exporter[15478]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:36:17 hn-dlp ipa-ods-exporter[15478]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:36:17 hn-dlp ipa-ods-exporter[15478]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:36:17 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:36:17 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:37:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:37:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:37:17 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:37:17 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 586. Jan 10 05:37:17 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:37:17 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:37:20 hn-dlp platform-python[15486]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:37:20 hn-dlp platform-python[15486]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:37:20 hn-dlp platform-python[15486]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:37:20 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15486]: new replica keys in LDAP: set() Jan 10 05:37:20 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15486]: obsolete replica keys in local HSM: set() Jan 10 05:37:20 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15486]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:37:20 hn-dlp ipa-ods-exporter[15486]: Traceback (most recent call last): Jan 10 05:37:20 hn-dlp ipa-ods-exporter[15486]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:37:20 hn-dlp ipa-ods-exporter[15486]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:37:20 hn-dlp ipa-ods-exporter[15486]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:37:20 hn-dlp ipa-ods-exporter[15486]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:37:20 hn-dlp ipa-ods-exporter[15486]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:37:20 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:37:20 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:38:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:38:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:38:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 587. Jan 10 05:38:21 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:38:21 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:38:23 hn-dlp platform-python[15498]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:38:23 hn-dlp platform-python[15498]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:38:23 hn-dlp platform-python[15498]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:38:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15498]: new replica keys in LDAP: set() Jan 10 05:38:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15498]: obsolete replica keys in local HSM: set() Jan 10 05:38:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15498]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:38:23 hn-dlp ipa-ods-exporter[15498]: Traceback (most recent call last): Jan 10 05:38:23 hn-dlp ipa-ods-exporter[15498]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:38:23 hn-dlp ipa-ods-exporter[15498]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:38:23 hn-dlp ipa-ods-exporter[15498]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:38:23 hn-dlp ipa-ods-exporter[15498]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:38:23 hn-dlp ipa-ods-exporter[15498]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:38:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:38:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:39:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:39:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:39:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:39:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 588. Jan 10 05:39:24 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:39:24 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:39:26 hn-dlp platform-python[15508]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:39:26 hn-dlp platform-python[15508]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:39:26 hn-dlp platform-python[15508]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:39:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15508]: new replica keys in LDAP: set() Jan 10 05:39:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15508]: obsolete replica keys in local HSM: set() Jan 10 05:39:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15508]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:39:27 hn-dlp ipa-ods-exporter[15508]: Traceback (most recent call last): Jan 10 05:39:27 hn-dlp ipa-ods-exporter[15508]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:39:27 hn-dlp ipa-ods-exporter[15508]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:39:27 hn-dlp ipa-ods-exporter[15508]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:39:27 hn-dlp ipa-ods-exporter[15508]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:39:27 hn-dlp ipa-ods-exporter[15508]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:39:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:39:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:40:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:40:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:40:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 589. Jan 10 05:40:27 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:40:27 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:40:30 hn-dlp platform-python[15517]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:40:30 hn-dlp platform-python[15517]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:40:30 hn-dlp platform-python[15517]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:40:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15517]: new replica keys in LDAP: set() Jan 10 05:40:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15517]: obsolete replica keys in local HSM: set() Jan 10 05:40:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15517]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:40:30 hn-dlp ipa-ods-exporter[15517]: Traceback (most recent call last): Jan 10 05:40:30 hn-dlp ipa-ods-exporter[15517]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:40:30 hn-dlp ipa-ods-exporter[15517]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:40:30 hn-dlp ipa-ods-exporter[15517]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:40:30 hn-dlp ipa-ods-exporter[15517]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:40:30 hn-dlp ipa-ods-exporter[15517]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:40:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:40:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:41:15 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:41:15 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:41:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:41:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 590. Jan 10 05:41:31 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:41:31 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:41:33 hn-dlp platform-python[15527]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:41:33 hn-dlp platform-python[15527]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:41:33 hn-dlp platform-python[15527]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:41:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15527]: new replica keys in LDAP: set() Jan 10 05:41:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15527]: obsolete replica keys in local HSM: set() Jan 10 05:41:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15527]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:41:33 hn-dlp ipa-ods-exporter[15527]: Traceback (most recent call last): Jan 10 05:41:33 hn-dlp ipa-ods-exporter[15527]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:41:33 hn-dlp ipa-ods-exporter[15527]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:41:33 hn-dlp ipa-ods-exporter[15527]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:41:33 hn-dlp ipa-ods-exporter[15527]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:41:33 hn-dlp ipa-ods-exporter[15527]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:41:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:41:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:42:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:42:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:42:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 591. Jan 10 05:42:34 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:42:34 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:42:36 hn-dlp platform-python[15536]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:42:36 hn-dlp platform-python[15536]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:42:36 hn-dlp platform-python[15536]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:42:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15536]: new replica keys in LDAP: set() Jan 10 05:42:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15536]: obsolete replica keys in local HSM: set() Jan 10 05:42:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15536]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:42:37 hn-dlp ipa-ods-exporter[15536]: Traceback (most recent call last): Jan 10 05:42:37 hn-dlp ipa-ods-exporter[15536]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:42:37 hn-dlp ipa-ods-exporter[15536]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:42:37 hn-dlp ipa-ods-exporter[15536]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:42:37 hn-dlp ipa-ods-exporter[15536]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:42:37 hn-dlp ipa-ods-exporter[15536]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:42:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:42:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:43:16 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:43:16 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:43:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:43:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 592. Jan 10 05:43:37 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:43:37 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:43:39 hn-dlp platform-python[15545]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:43:39 hn-dlp platform-python[15545]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:43:39 hn-dlp platform-python[15545]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:43:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15545]: new replica keys in LDAP: set() Jan 10 05:43:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15545]: obsolete replica keys in local HSM: set() Jan 10 05:43:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15545]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:43:40 hn-dlp ipa-ods-exporter[15545]: Traceback (most recent call last): Jan 10 05:43:40 hn-dlp ipa-ods-exporter[15545]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:43:40 hn-dlp ipa-ods-exporter[15545]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:43:40 hn-dlp ipa-ods-exporter[15545]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:43:40 hn-dlp ipa-ods-exporter[15545]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:43:40 hn-dlp ipa-ods-exporter[15545]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:43:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:43:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:44:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:44:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:44:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 593. Jan 10 05:44:40 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:44:40 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:44:43 hn-dlp platform-python[15555]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:44:43 hn-dlp platform-python[15555]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:44:43 hn-dlp platform-python[15555]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:44:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15555]: new replica keys in LDAP: set() Jan 10 05:44:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15555]: obsolete replica keys in local HSM: set() Jan 10 05:44:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15555]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:44:43 hn-dlp ipa-ods-exporter[15555]: Traceback (most recent call last): Jan 10 05:44:43 hn-dlp ipa-ods-exporter[15555]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:44:43 hn-dlp ipa-ods-exporter[15555]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:44:43 hn-dlp ipa-ods-exporter[15555]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:44:43 hn-dlp ipa-ods-exporter[15555]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:44:43 hn-dlp ipa-ods-exporter[15555]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:44:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:44:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:45:16 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 05:45:16 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:45:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:45:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 594. Jan 10 05:45:44 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:45:44 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:45:46 hn-dlp platform-python[15565]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:45:46 hn-dlp platform-python[15565]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:45:46 hn-dlp platform-python[15565]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:45:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15565]: new replica keys in LDAP: set() Jan 10 05:45:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15565]: obsolete replica keys in local HSM: set() Jan 10 05:45:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15565]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:45:46 hn-dlp ipa-ods-exporter[15565]: Traceback (most recent call last): Jan 10 05:45:46 hn-dlp ipa-ods-exporter[15565]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:45:46 hn-dlp ipa-ods-exporter[15565]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:45:46 hn-dlp ipa-ods-exporter[15565]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:45:46 hn-dlp ipa-ods-exporter[15565]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:45:46 hn-dlp ipa-ods-exporter[15565]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:45:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:45:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:46:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:46:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:46:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 595. Jan 10 05:46:47 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:46:47 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:46:49 hn-dlp platform-python[15573]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:46:49 hn-dlp platform-python[15573]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:46:49 hn-dlp platform-python[15573]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:46:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15573]: new replica keys in LDAP: set() Jan 10 05:46:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15573]: obsolete replica keys in local HSM: set() Jan 10 05:46:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15573]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:46:49 hn-dlp ipa-ods-exporter[15573]: Traceback (most recent call last): Jan 10 05:46:49 hn-dlp ipa-ods-exporter[15573]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:46:49 hn-dlp ipa-ods-exporter[15573]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:46:49 hn-dlp ipa-ods-exporter[15573]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:46:49 hn-dlp ipa-ods-exporter[15573]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:46:49 hn-dlp ipa-ods-exporter[15573]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:46:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:46:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:47:16 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:47:16 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:47:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:47:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 596. Jan 10 05:47:50 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:47:50 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:47:52 hn-dlp platform-python[15582]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:47:52 hn-dlp platform-python[15582]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:47:52 hn-dlp platform-python[15582]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:47:53 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15582]: new replica keys in LDAP: set() Jan 10 05:47:53 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15582]: obsolete replica keys in local HSM: set() Jan 10 05:47:53 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15582]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:47:53 hn-dlp ipa-ods-exporter[15582]: Traceback (most recent call last): Jan 10 05:47:53 hn-dlp ipa-ods-exporter[15582]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:47:53 hn-dlp ipa-ods-exporter[15582]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:47:53 hn-dlp ipa-ods-exporter[15582]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:47:53 hn-dlp ipa-ods-exporter[15582]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:47:53 hn-dlp ipa-ods-exporter[15582]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:47:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:47:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:48:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:48:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:48:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 597. Jan 10 05:48:53 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:48:53 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:48:56 hn-dlp platform-python[15593]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:48:56 hn-dlp platform-python[15593]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:48:56 hn-dlp platform-python[15593]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:48:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15593]: new replica keys in LDAP: set() Jan 10 05:48:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15593]: obsolete replica keys in local HSM: set() Jan 10 05:48:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15593]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:48:56 hn-dlp ipa-ods-exporter[15593]: Traceback (most recent call last): Jan 10 05:48:56 hn-dlp ipa-ods-exporter[15593]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:48:56 hn-dlp ipa-ods-exporter[15593]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:48:56 hn-dlp ipa-ods-exporter[15593]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:48:56 hn-dlp ipa-ods-exporter[15593]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:48:56 hn-dlp ipa-ods-exporter[15593]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:48:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:48:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:49:16 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:49:16 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:49:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:49:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 598. Jan 10 05:49:56 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:49:56 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:49:59 hn-dlp platform-python[15602]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:49:59 hn-dlp platform-python[15602]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:49:59 hn-dlp platform-python[15602]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:49:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15602]: new replica keys in LDAP: set() Jan 10 05:49:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15602]: obsolete replica keys in local HSM: set() Jan 10 05:49:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15602]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:49:59 hn-dlp ipa-ods-exporter[15602]: Traceback (most recent call last): Jan 10 05:49:59 hn-dlp ipa-ods-exporter[15602]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:49:59 hn-dlp ipa-ods-exporter[15602]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:49:59 hn-dlp ipa-ods-exporter[15602]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:49:59 hn-dlp ipa-ods-exporter[15602]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:49:59 hn-dlp ipa-ods-exporter[15602]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:49:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:49:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:50:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:51:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:51:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 599. Jan 10 05:51:00 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:51:00 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:51:02 hn-dlp platform-python[15615]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:51:02 hn-dlp platform-python[15615]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:51:02 hn-dlp platform-python[15615]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:51:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15615]: new replica keys in LDAP: set() Jan 10 05:51:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15615]: obsolete replica keys in local HSM: set() Jan 10 05:51:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15615]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:51:02 hn-dlp ipa-ods-exporter[15615]: Traceback (most recent call last): Jan 10 05:51:02 hn-dlp ipa-ods-exporter[15615]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:51:02 hn-dlp ipa-ods-exporter[15615]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:51:02 hn-dlp ipa-ods-exporter[15615]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:51:02 hn-dlp ipa-ods-exporter[15615]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:51:02 hn-dlp ipa-ods-exporter[15615]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:51:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:51:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:51:16 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:51:16 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:52:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:52:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 600. Jan 10 05:52:03 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:52:03 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:52:05 hn-dlp platform-python[15625]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:52:05 hn-dlp platform-python[15625]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:52:05 hn-dlp platform-python[15625]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:52:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15625]: new replica keys in LDAP: set() Jan 10 05:52:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15625]: obsolete replica keys in local HSM: set() Jan 10 05:52:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15625]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:52:06 hn-dlp ipa-ods-exporter[15625]: Traceback (most recent call last): Jan 10 05:52:06 hn-dlp ipa-ods-exporter[15625]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:52:06 hn-dlp ipa-ods-exporter[15625]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:52:06 hn-dlp ipa-ods-exporter[15625]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:52:06 hn-dlp ipa-ods-exporter[15625]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:52:06 hn-dlp ipa-ods-exporter[15625]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:52:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:52:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:52:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:53:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:53:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 601. Jan 10 05:53:06 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:53:06 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:53:08 hn-dlp platform-python[15634]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:53:08 hn-dlp platform-python[15634]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:53:08 hn-dlp platform-python[15634]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:53:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15634]: new replica keys in LDAP: set() Jan 10 05:53:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15634]: obsolete replica keys in local HSM: set() Jan 10 05:53:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15634]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:53:09 hn-dlp ipa-ods-exporter[15634]: Traceback (most recent call last): Jan 10 05:53:09 hn-dlp ipa-ods-exporter[15634]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:53:09 hn-dlp ipa-ods-exporter[15634]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:53:09 hn-dlp ipa-ods-exporter[15634]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:53:09 hn-dlp ipa-ods-exporter[15634]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:53:09 hn-dlp ipa-ods-exporter[15634]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:53:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:53:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:53:16 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:53:16 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:54:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:54:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 602. Jan 10 05:54:09 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:54:09 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:54:12 hn-dlp platform-python[15642]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:54:12 hn-dlp platform-python[15642]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:54:12 hn-dlp platform-python[15642]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:54:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15642]: new replica keys in LDAP: set() Jan 10 05:54:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15642]: obsolete replica keys in local HSM: set() Jan 10 05:54:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15642]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:54:12 hn-dlp ipa-ods-exporter[15642]: Traceback (most recent call last): Jan 10 05:54:12 hn-dlp ipa-ods-exporter[15642]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:54:12 hn-dlp ipa-ods-exporter[15642]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:54:12 hn-dlp ipa-ods-exporter[15642]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:54:12 hn-dlp ipa-ods-exporter[15642]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:54:12 hn-dlp ipa-ods-exporter[15642]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:54:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:54:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:54:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:55:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:55:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 603. Jan 10 05:55:13 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:55:13 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:55:15 hn-dlp platform-python[15651]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:55:15 hn-dlp platform-python[15651]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:55:15 hn-dlp platform-python[15651]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:55:15 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15651]: new replica keys in LDAP: set() Jan 10 05:55:15 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15651]: obsolete replica keys in local HSM: set() Jan 10 05:55:15 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15651]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:55:15 hn-dlp ipa-ods-exporter[15651]: Traceback (most recent call last): Jan 10 05:55:15 hn-dlp ipa-ods-exporter[15651]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:55:15 hn-dlp ipa-ods-exporter[15651]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:55:15 hn-dlp ipa-ods-exporter[15651]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:55:15 hn-dlp ipa-ods-exporter[15651]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:55:15 hn-dlp ipa-ods-exporter[15651]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:55:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:55:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:55:17 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 05:55:17 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:56:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:56:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 604. Jan 10 05:56:16 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:56:16 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:56:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:56:18 hn-dlp platform-python[15662]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:56:18 hn-dlp platform-python[15662]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:56:18 hn-dlp platform-python[15662]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:56:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15662]: new replica keys in LDAP: set() Jan 10 05:56:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15662]: obsolete replica keys in local HSM: set() Jan 10 05:56:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15662]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:56:19 hn-dlp ipa-ods-exporter[15662]: Traceback (most recent call last): Jan 10 05:56:19 hn-dlp ipa-ods-exporter[15662]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:56:19 hn-dlp ipa-ods-exporter[15662]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:56:19 hn-dlp ipa-ods-exporter[15662]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:56:19 hn-dlp ipa-ods-exporter[15662]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:56:19 hn-dlp ipa-ods-exporter[15662]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:56:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:56:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:57:17 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:57:17 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:57:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:57:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 605. Jan 10 05:57:19 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:57:19 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:57:22 hn-dlp platform-python[15672]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:57:22 hn-dlp platform-python[15672]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:57:22 hn-dlp platform-python[15672]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:57:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15672]: new replica keys in LDAP: set() Jan 10 05:57:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15672]: obsolete replica keys in local HSM: set() Jan 10 05:57:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15672]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:57:22 hn-dlp ipa-ods-exporter[15672]: Traceback (most recent call last): Jan 10 05:57:22 hn-dlp ipa-ods-exporter[15672]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:57:22 hn-dlp ipa-ods-exporter[15672]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:57:22 hn-dlp ipa-ods-exporter[15672]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:57:22 hn-dlp ipa-ods-exporter[15672]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:57:22 hn-dlp ipa-ods-exporter[15672]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:57:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:57:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:58:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 05:58:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:58:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 606. Jan 10 05:58:22 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:58:22 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:58:25 hn-dlp platform-python[15682]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:58:25 hn-dlp platform-python[15682]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:58:25 hn-dlp platform-python[15682]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:58:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15682]: new replica keys in LDAP: set() Jan 10 05:58:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15682]: obsolete replica keys in local HSM: set() Jan 10 05:58:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15682]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 05:58:25 hn-dlp ipa-ods-exporter[15682]: Traceback (most recent call last): Jan 10 05:58:25 hn-dlp ipa-ods-exporter[15682]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:58:25 hn-dlp ipa-ods-exporter[15682]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:58:25 hn-dlp ipa-ods-exporter[15682]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:58:25 hn-dlp ipa-ods-exporter[15682]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:58:25 hn-dlp ipa-ods-exporter[15682]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:58:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:58:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 05:59:17 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 05:59:17 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 05:59:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 05:59:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 607. Jan 10 05:59:26 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 05:59:26 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 05:59:28 hn-dlp platform-python[15693]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 05:59:28 hn-dlp platform-python[15693]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 05:59:28 hn-dlp platform-python[15693]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 05:59:28 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15693]: new replica keys in LDAP: set() Jan 10 05:59:28 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15693]: obsolete replica keys in local HSM: set() Jan 10 05:59:28 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15693]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 05:59:28 hn-dlp ipa-ods-exporter[15693]: Traceback (most recent call last): Jan 10 05:59:28 hn-dlp ipa-ods-exporter[15693]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 05:59:28 hn-dlp ipa-ods-exporter[15693]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 05:59:28 hn-dlp ipa-ods-exporter[15693]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 05:59:28 hn-dlp ipa-ods-exporter[15693]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 05:59:28 hn-dlp ipa-ods-exporter[15693]: KeyError: 'popitem(): dictionary is empty' Jan 10 05:59:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 05:59:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:00:00 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '168.192.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 06:00:00 hn-dlp named-pkcs11[1516]: no valid DS resolving '2.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:00 hn-dlp named-pkcs11[1516]: validating 4.133.168.192.in-addr.arpa/PTR: bad cache hit (168.192.in-addr.arpa/DS) Jan 10 06:00:00 hn-dlp named-pkcs11[1516]: broken trust chain resolving '4.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:00 hn-dlp named-pkcs11[1516]: validating 3.133.168.192.in-addr.arpa/PTR: bad cache hit (168.192.in-addr.arpa/DS) Jan 10 06:00:00 hn-dlp named-pkcs11[1516]: broken trust chain resolving '3.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:02 hn-dlp named-pkcs11[1516]: validating 104.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '104.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:02 hn-dlp named-pkcs11[1516]: validating 109.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:02 hn-dlp named-pkcs11[1516]: broken trust chain resolving '109.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 110.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '110.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 113.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '113.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 191.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '191.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 192.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '192.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 203.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '203.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 254.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '254.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 104.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '104.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 171.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '171.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 173.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '173.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 183.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '183.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 204.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '204.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 213.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '213.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 216.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '216.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 217.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '217.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 1.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 5.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '5.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 14.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '14.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 15.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '15.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 1.171.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.171.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 2.171.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '2.171.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 100.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '100.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 103.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '103.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 254.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '254.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 104.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '104.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: validating 107.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:03 hn-dlp named-pkcs11[1516]: broken trust chain resolving '107.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:04 hn-dlp named-pkcs11[1516]: validating 254.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:04 hn-dlp named-pkcs11[1516]: broken trust chain resolving '254.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:04 hn-dlp named-pkcs11[1516]: validating 5.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:04 hn-dlp named-pkcs11[1516]: broken trust chain resolving '5.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:04 hn-dlp named-pkcs11[1516]: validating 11.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:04 hn-dlp named-pkcs11[1516]: broken trust chain resolving '11.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:04 hn-dlp named-pkcs11[1516]: validating 100.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:04 hn-dlp named-pkcs11[1516]: broken trust chain resolving '100.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:04 hn-dlp named-pkcs11[1516]: validating 254.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:00:04 hn-dlp named-pkcs11[1516]: broken trust chain resolving '254.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:00:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:00:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:00:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 608. Jan 10 06:00:29 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:00:29 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:00:31 hn-dlp platform-python[15701]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:00:31 hn-dlp platform-python[15701]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:00:31 hn-dlp platform-python[15701]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:00:31 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15701]: new replica keys in LDAP: set() Jan 10 06:00:31 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15701]: obsolete replica keys in local HSM: set() Jan 10 06:00:31 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[15701]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:00:32 hn-dlp ipa-ods-exporter[15701]: Traceback (most recent call last): Jan 10 06:00:32 hn-dlp ipa-ods-exporter[15701]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:00:32 hn-dlp ipa-ods-exporter[15701]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:00:32 hn-dlp ipa-ods-exporter[15701]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:00:32 hn-dlp ipa-ods-exporter[15701]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:00:32 hn-dlp ipa-ods-exporter[15701]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:00:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:00:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:00:35 hn-dlp systemd[1]: Started /run/user/2002 mount wrapper. Jan 10 06:00:35 hn-dlp systemd[1]: Created slice User Slice of UID 2002. Jan 10 06:00:35 hn-dlp systemd[1]: Starting User Manager for UID 2002... Jan 10 06:00:35 hn-dlp systemd-logind[736]: New session 46 of user svcforeman. Jan 10 06:00:35 hn-dlp systemd[1]: Started Session 46 of user svcforeman. Jan 10 06:00:36 hn-dlp systemd[15716]: Started Mark boot as successful after the user session has run 2 minutes. Jan 10 06:00:36 hn-dlp systemd[15716]: Reached target Paths. Jan 10 06:00:36 hn-dlp systemd[15716]: Starting D-Bus User Message Bus Socket. Jan 10 06:00:36 hn-dlp systemd[15716]: Reached target Timers. Jan 10 06:00:36 hn-dlp systemd[15716]: Listening on D-Bus User Message Bus Socket. Jan 10 06:00:36 hn-dlp systemd[15716]: Reached target Sockets. Jan 10 06:00:36 hn-dlp systemd[15716]: Reached target Basic System. Jan 10 06:00:36 hn-dlp systemd[15716]: Reached target Default. Jan 10 06:00:36 hn-dlp systemd[15716]: Startup finished in 71ms. Jan 10 06:00:36 hn-dlp systemd[1]: Started User Manager for UID 2002. Jan 10 06:00:39 hn-dlp platform-python[15878]: ansible-setup Invoked with gather_timeout=10 gather_subset=['all'] filter=* fact_path=/etc/ansible/facts.d Jan 10 06:01:04 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.131' (uid=0 pid=669 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 06:01:04 hn-dlp dbus-daemon[16061]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 06:01:05 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 06:01:05 hn-dlp setroubleshoot[16061]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der Jan 10 06:01:05 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.1118' (uid=995 pid=16061 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 06:01:05 hn-dlp dbus-daemon[16074]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 06:01:06 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 06:01:09 hn-dlp setroubleshoot[16061]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 06:01:09 hn-dlp setroubleshoot[16061]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-050000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 06:01:17 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:01:17 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:01:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:01:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 609. Jan 10 06:01:32 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:01:32 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.131' (uid=0 pid=669 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 06:01:32 hn-dlp dbus-daemon[16080]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 06:01:32 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:01:35 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 06:01:36 hn-dlp setroubleshoot[16080]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der Jan 10 06:01:36 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.1124' (uid=995 pid=16080 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 06:01:36 hn-dlp dbus-daemon[16097]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 06:01:38 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 06:01:38 hn-dlp platform-python[16081]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:01:38 hn-dlp platform-python[16081]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:01:38 hn-dlp platform-python[16081]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:01:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16081]: new replica keys in LDAP: set() Jan 10 06:01:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16081]: obsolete replica keys in local HSM: set() Jan 10 06:01:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16081]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:01:38 hn-dlp ipa-ods-exporter[16081]: Traceback (most recent call last): Jan 10 06:01:38 hn-dlp ipa-ods-exporter[16081]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:01:38 hn-dlp ipa-ods-exporter[16081]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:01:38 hn-dlp ipa-ods-exporter[16081]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:01:38 hn-dlp ipa-ods-exporter[16081]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:01:38 hn-dlp ipa-ods-exporter[16081]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:01:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:01:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:01:40 hn-dlp setroubleshoot[16080]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 06:01:40 hn-dlp setroubleshoot[16080]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-050000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 06:01:42 hn-dlp systemd-logind[736]: Session 46 logged out. Waiting for processes to exit. Jan 10 06:01:42 hn-dlp systemd[1]: session-46.scope: Succeeded. Jan 10 06:01:42 hn-dlp systemd-logind[736]: Removed session 46. Jan 10 06:01:42 hn-dlp systemd[1]: Stopping User Manager for UID 2002... Jan 10 06:01:42 hn-dlp systemd[15716]: Stopped target Default. Jan 10 06:01:42 hn-dlp systemd[15716]: Stopped target Basic System. Jan 10 06:01:42 hn-dlp systemd[15716]: Stopped target Paths. Jan 10 06:01:42 hn-dlp systemd[15716]: Stopped target Sockets. Jan 10 06:01:42 hn-dlp systemd[15716]: dbus.socket: Succeeded. Jan 10 06:01:42 hn-dlp systemd[15716]: Closed D-Bus User Message Bus Socket. Jan 10 06:01:42 hn-dlp systemd[15716]: Stopped target Timers. Jan 10 06:01:42 hn-dlp systemd[15716]: grub-boot-success.timer: Succeeded. Jan 10 06:01:42 hn-dlp systemd[15716]: Stopped Mark boot as successful after the user session has run 2 minutes. Jan 10 06:01:42 hn-dlp systemd[15716]: Reached target Shutdown. Jan 10 06:01:42 hn-dlp systemd[15716]: Starting Exit the Session... Jan 10 06:01:42 hn-dlp systemd[1]: user@2002.service: Succeeded. Jan 10 06:01:42 hn-dlp systemd[1]: Stopped User Manager for UID 2002. Jan 10 06:01:42 hn-dlp systemd[1]: Stopping /run/user/2002 mount wrapper... Jan 10 06:01:42 hn-dlp systemd[1]: Removed slice User Slice of UID 2002. Jan 10 06:01:42 hn-dlp systemd[1]: run-user-2002.mount: Succeeded. Jan 10 06:01:42 hn-dlp systemd[1]: user-runtime-dir@2002.service: Succeeded. Jan 10 06:01:42 hn-dlp systemd[1]: Stopped /run/user/2002 mount wrapper. Jan 10 06:02:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:02:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:02:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 610. Jan 10 06:02:39 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:02:39 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:02:43 hn-dlp platform-python[16116]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:02:43 hn-dlp platform-python[16116]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:02:43 hn-dlp platform-python[16116]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:02:44 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16116]: new replica keys in LDAP: set() Jan 10 06:02:44 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16116]: obsolete replica keys in local HSM: set() Jan 10 06:02:44 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16116]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 06:02:44 hn-dlp ipa-ods-exporter[16116]: Traceback (most recent call last): Jan 10 06:02:44 hn-dlp ipa-ods-exporter[16116]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:02:44 hn-dlp ipa-ods-exporter[16116]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:02:44 hn-dlp ipa-ods-exporter[16116]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:02:44 hn-dlp ipa-ods-exporter[16116]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:02:44 hn-dlp ipa-ods-exporter[16116]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:02:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:02:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:03:17 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:03:17 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:03:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:03:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 611. Jan 10 06:03:44 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:03:44 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:03:45 hn-dlp rsyslogd[1013]: imjournal: journal files changed, reloading... [v8.1911.0-6.el8 try https://www.rsyslog.com/e/0 ] Jan 10 06:03:46 hn-dlp platform-python[16126]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:03:46 hn-dlp platform-python[16126]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:03:46 hn-dlp platform-python[16126]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:03:47 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16126]: new replica keys in LDAP: set() Jan 10 06:03:47 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16126]: obsolete replica keys in local HSM: set() Jan 10 06:03:47 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16126]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 06:03:47 hn-dlp ipa-ods-exporter[16126]: Traceback (most recent call last): Jan 10 06:03:47 hn-dlp ipa-ods-exporter[16126]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:03:47 hn-dlp ipa-ods-exporter[16126]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:03:47 hn-dlp ipa-ods-exporter[16126]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:03:47 hn-dlp ipa-ods-exporter[16126]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:03:47 hn-dlp ipa-ods-exporter[16126]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:03:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:03:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:04:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:04:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:04:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 612. Jan 10 06:04:47 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:04:47 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:04:50 hn-dlp platform-python[16136]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:04:50 hn-dlp platform-python[16136]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:04:50 hn-dlp platform-python[16136]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:04:50 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16136]: new replica keys in LDAP: set() Jan 10 06:04:50 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16136]: obsolete replica keys in local HSM: set() Jan 10 06:04:50 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16136]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:04:50 hn-dlp ipa-ods-exporter[16136]: Traceback (most recent call last): Jan 10 06:04:50 hn-dlp ipa-ods-exporter[16136]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:04:50 hn-dlp ipa-ods-exporter[16136]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:04:50 hn-dlp ipa-ods-exporter[16136]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:04:50 hn-dlp ipa-ods-exporter[16136]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:04:50 hn-dlp ipa-ods-exporter[16136]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:04:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:04:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:05:17 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 06:05:17 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:05:51 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:05:51 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 613. Jan 10 06:05:51 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:05:51 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:05:53 hn-dlp platform-python[16146]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:05:53 hn-dlp platform-python[16146]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:05:53 hn-dlp platform-python[16146]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:05:53 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16146]: new replica keys in LDAP: set() Jan 10 06:05:53 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16146]: obsolete replica keys in local HSM: set() Jan 10 06:05:53 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16146]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:05:53 hn-dlp ipa-ods-exporter[16146]: Traceback (most recent call last): Jan 10 06:05:53 hn-dlp ipa-ods-exporter[16146]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:05:53 hn-dlp ipa-ods-exporter[16146]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:05:53 hn-dlp ipa-ods-exporter[16146]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:05:53 hn-dlp ipa-ods-exporter[16146]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:05:53 hn-dlp ipa-ods-exporter[16146]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:05:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:05:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:06:17 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:06:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:06:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 614. Jan 10 06:06:54 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:06:54 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:06:56 hn-dlp platform-python[16156]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:06:56 hn-dlp platform-python[16156]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:06:56 hn-dlp platform-python[16156]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:06:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16156]: new replica keys in LDAP: set() Jan 10 06:06:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16156]: obsolete replica keys in local HSM: set() Jan 10 06:06:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16156]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 06:06:56 hn-dlp ipa-ods-exporter[16156]: Traceback (most recent call last): Jan 10 06:06:56 hn-dlp ipa-ods-exporter[16156]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:06:56 hn-dlp ipa-ods-exporter[16156]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:06:56 hn-dlp ipa-ods-exporter[16156]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:06:56 hn-dlp ipa-ods-exporter[16156]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:06:56 hn-dlp ipa-ods-exporter[16156]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:06:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:06:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:07:17 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:07:17 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:07:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:07:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 615. Jan 10 06:07:57 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:07:57 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:07:59 hn-dlp platform-python[16164]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:07:59 hn-dlp platform-python[16164]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:07:59 hn-dlp platform-python[16164]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:08:00 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16164]: new replica keys in LDAP: set() Jan 10 06:08:00 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16164]: obsolete replica keys in local HSM: set() Jan 10 06:08:00 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16164]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:08:00 hn-dlp ipa-ods-exporter[16164]: Traceback (most recent call last): Jan 10 06:08:00 hn-dlp ipa-ods-exporter[16164]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:08:00 hn-dlp ipa-ods-exporter[16164]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:08:00 hn-dlp ipa-ods-exporter[16164]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:08:00 hn-dlp ipa-ods-exporter[16164]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:08:00 hn-dlp ipa-ods-exporter[16164]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:08:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:08:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:08:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:09:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:09:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 616. Jan 10 06:09:00 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:09:00 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:09:03 hn-dlp platform-python[16174]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:09:03 hn-dlp platform-python[16174]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:09:03 hn-dlp platform-python[16174]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:09:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16174]: new replica keys in LDAP: set() Jan 10 06:09:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16174]: obsolete replica keys in local HSM: set() Jan 10 06:09:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16174]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 06:09:03 hn-dlp ipa-ods-exporter[16174]: Traceback (most recent call last): Jan 10 06:09:03 hn-dlp ipa-ods-exporter[16174]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:09:03 hn-dlp ipa-ods-exporter[16174]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:09:03 hn-dlp ipa-ods-exporter[16174]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:09:03 hn-dlp ipa-ods-exporter[16174]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:09:03 hn-dlp ipa-ods-exporter[16174]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:09:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:09:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:09:17 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:09:17 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:10:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:10:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 617. Jan 10 06:10:03 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:10:03 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:10:06 hn-dlp platform-python[16183]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:10:06 hn-dlp platform-python[16183]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:10:06 hn-dlp platform-python[16183]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:10:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16183]: new replica keys in LDAP: set() Jan 10 06:10:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16183]: obsolete replica keys in local HSM: set() Jan 10 06:10:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16183]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:10:06 hn-dlp ipa-ods-exporter[16183]: Traceback (most recent call last): Jan 10 06:10:06 hn-dlp ipa-ods-exporter[16183]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:10:06 hn-dlp ipa-ods-exporter[16183]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:10:06 hn-dlp ipa-ods-exporter[16183]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:10:06 hn-dlp ipa-ods-exporter[16183]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:10:06 hn-dlp ipa-ods-exporter[16183]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:10:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:10:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:10:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:11:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:11:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 618. Jan 10 06:11:06 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:11:06 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:11:09 hn-dlp platform-python[16192]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:11:09 hn-dlp platform-python[16192]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:11:09 hn-dlp platform-python[16192]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:11:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16192]: new replica keys in LDAP: set() Jan 10 06:11:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16192]: obsolete replica keys in local HSM: set() Jan 10 06:11:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16192]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:11:09 hn-dlp ipa-ods-exporter[16192]: Traceback (most recent call last): Jan 10 06:11:09 hn-dlp ipa-ods-exporter[16192]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:11:09 hn-dlp ipa-ods-exporter[16192]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:11:09 hn-dlp ipa-ods-exporter[16192]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:11:09 hn-dlp ipa-ods-exporter[16192]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:11:09 hn-dlp ipa-ods-exporter[16192]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:11:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:11:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:11:17 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:11:17 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:12:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:12:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 619. Jan 10 06:12:10 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:12:10 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:12:12 hn-dlp platform-python[16203]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:12:12 hn-dlp platform-python[16203]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:12:12 hn-dlp platform-python[16203]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:12:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16203]: new replica keys in LDAP: set() Jan 10 06:12:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16203]: obsolete replica keys in local HSM: set() Jan 10 06:12:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16203]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:12:12 hn-dlp ipa-ods-exporter[16203]: Traceback (most recent call last): Jan 10 06:12:12 hn-dlp ipa-ods-exporter[16203]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:12:12 hn-dlp ipa-ods-exporter[16203]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:12:12 hn-dlp ipa-ods-exporter[16203]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:12:12 hn-dlp ipa-ods-exporter[16203]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:12:12 hn-dlp ipa-ods-exporter[16203]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:12:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:12:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:12:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:13:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:13:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 620. Jan 10 06:13:13 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:13:13 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:13:15 hn-dlp platform-python[16211]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:13:15 hn-dlp platform-python[16211]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:13:15 hn-dlp platform-python[16211]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:13:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16211]: new replica keys in LDAP: set() Jan 10 06:13:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16211]: obsolete replica keys in local HSM: set() Jan 10 06:13:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16211]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:13:16 hn-dlp ipa-ods-exporter[16211]: Traceback (most recent call last): Jan 10 06:13:16 hn-dlp ipa-ods-exporter[16211]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:13:16 hn-dlp ipa-ods-exporter[16211]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:13:16 hn-dlp ipa-ods-exporter[16211]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:13:16 hn-dlp ipa-ods-exporter[16211]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:13:16 hn-dlp ipa-ods-exporter[16211]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:13:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:13:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:13:18 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:13:18 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:14:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:14:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 621. Jan 10 06:14:16 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:14:16 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:14:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:14:19 hn-dlp platform-python[16220]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:14:19 hn-dlp platform-python[16220]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:14:19 hn-dlp platform-python[16220]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:14:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16220]: new replica keys in LDAP: set() Jan 10 06:14:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16220]: obsolete replica keys in local HSM: set() Jan 10 06:14:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16220]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:14:19 hn-dlp ipa-ods-exporter[16220]: Traceback (most recent call last): Jan 10 06:14:19 hn-dlp ipa-ods-exporter[16220]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:14:19 hn-dlp ipa-ods-exporter[16220]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:14:19 hn-dlp ipa-ods-exporter[16220]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:14:19 hn-dlp ipa-ods-exporter[16220]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:14:19 hn-dlp ipa-ods-exporter[16220]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:14:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:14:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:15:18 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 06:15:18 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:15:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:15:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 622. Jan 10 06:15:19 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:15:19 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:15:22 hn-dlp platform-python[16232]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:15:22 hn-dlp platform-python[16232]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:15:22 hn-dlp platform-python[16232]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:15:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16232]: new replica keys in LDAP: set() Jan 10 06:15:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16232]: obsolete replica keys in local HSM: set() Jan 10 06:15:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16232]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:15:22 hn-dlp ipa-ods-exporter[16232]: Traceback (most recent call last): Jan 10 06:15:22 hn-dlp ipa-ods-exporter[16232]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:15:22 hn-dlp ipa-ods-exporter[16232]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:15:22 hn-dlp ipa-ods-exporter[16232]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:15:22 hn-dlp ipa-ods-exporter[16232]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:15:22 hn-dlp ipa-ods-exporter[16232]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:15:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:15:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:16:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:16:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:16:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 623. Jan 10 06:16:23 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:16:23 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:16:25 hn-dlp platform-python[16240]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:16:25 hn-dlp platform-python[16240]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:16:25 hn-dlp platform-python[16240]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:16:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16240]: new replica keys in LDAP: set() Jan 10 06:16:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16240]: obsolete replica keys in local HSM: set() Jan 10 06:16:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16240]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:16:25 hn-dlp ipa-ods-exporter[16240]: Traceback (most recent call last): Jan 10 06:16:25 hn-dlp ipa-ods-exporter[16240]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:16:25 hn-dlp ipa-ods-exporter[16240]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:16:25 hn-dlp ipa-ods-exporter[16240]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:16:25 hn-dlp ipa-ods-exporter[16240]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:16:25 hn-dlp ipa-ods-exporter[16240]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:16:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:16:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:17:18 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:17:18 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:17:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:17:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 624. Jan 10 06:17:26 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:17:26 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:17:28 hn-dlp platform-python[16249]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:17:28 hn-dlp platform-python[16249]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:17:28 hn-dlp platform-python[16249]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:17:28 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16249]: new replica keys in LDAP: set() Jan 10 06:17:28 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16249]: obsolete replica keys in local HSM: set() Jan 10 06:17:28 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16249]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:17:28 hn-dlp ipa-ods-exporter[16249]: Traceback (most recent call last): Jan 10 06:17:28 hn-dlp ipa-ods-exporter[16249]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:17:28 hn-dlp ipa-ods-exporter[16249]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:17:28 hn-dlp ipa-ods-exporter[16249]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:17:28 hn-dlp ipa-ods-exporter[16249]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:17:28 hn-dlp ipa-ods-exporter[16249]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:17:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:17:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:18:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:18:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:18:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 625. Jan 10 06:18:29 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:18:29 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:18:31 hn-dlp platform-python[16257]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:18:31 hn-dlp platform-python[16257]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:18:31 hn-dlp platform-python[16257]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:18:32 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16257]: new replica keys in LDAP: set() Jan 10 06:18:32 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16257]: obsolete replica keys in local HSM: set() Jan 10 06:18:32 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16257]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:18:32 hn-dlp ipa-ods-exporter[16257]: Traceback (most recent call last): Jan 10 06:18:32 hn-dlp ipa-ods-exporter[16257]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:18:32 hn-dlp ipa-ods-exporter[16257]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:18:32 hn-dlp ipa-ods-exporter[16257]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:18:32 hn-dlp ipa-ods-exporter[16257]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:18:32 hn-dlp ipa-ods-exporter[16257]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:18:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:18:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:19:18 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:19:18 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:19:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:19:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 626. Jan 10 06:19:32 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:19:32 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:19:35 hn-dlp platform-python[16267]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:19:35 hn-dlp platform-python[16267]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:19:35 hn-dlp platform-python[16267]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:19:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16267]: new replica keys in LDAP: set() Jan 10 06:19:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16267]: obsolete replica keys in local HSM: set() Jan 10 06:19:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16267]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:19:35 hn-dlp ipa-ods-exporter[16267]: Traceback (most recent call last): Jan 10 06:19:35 hn-dlp ipa-ods-exporter[16267]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:19:35 hn-dlp ipa-ods-exporter[16267]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:19:35 hn-dlp ipa-ods-exporter[16267]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:19:35 hn-dlp ipa-ods-exporter[16267]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:19:35 hn-dlp ipa-ods-exporter[16267]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:19:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:19:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:20:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:20:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:20:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 627. Jan 10 06:20:35 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:20:35 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:20:38 hn-dlp platform-python[16278]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:20:38 hn-dlp platform-python[16278]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:20:38 hn-dlp platform-python[16278]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:20:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16278]: new replica keys in LDAP: set() Jan 10 06:20:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16278]: obsolete replica keys in local HSM: set() Jan 10 06:20:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16278]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 06:20:38 hn-dlp ipa-ods-exporter[16278]: Traceback (most recent call last): Jan 10 06:20:38 hn-dlp ipa-ods-exporter[16278]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:20:38 hn-dlp ipa-ods-exporter[16278]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:20:38 hn-dlp ipa-ods-exporter[16278]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:20:38 hn-dlp ipa-ods-exporter[16278]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:20:38 hn-dlp ipa-ods-exporter[16278]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:20:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:20:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:21:18 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:21:18 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:21:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:21:39 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 628. Jan 10 06:21:39 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:21:39 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:21:41 hn-dlp platform-python[16288]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:21:41 hn-dlp platform-python[16288]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:21:41 hn-dlp platform-python[16288]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:21:41 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16288]: new replica keys in LDAP: set() Jan 10 06:21:41 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16288]: obsolete replica keys in local HSM: set() Jan 10 06:21:41 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16288]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:21:41 hn-dlp ipa-ods-exporter[16288]: Traceback (most recent call last): Jan 10 06:21:41 hn-dlp ipa-ods-exporter[16288]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:21:41 hn-dlp ipa-ods-exporter[16288]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:21:41 hn-dlp ipa-ods-exporter[16288]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:21:41 hn-dlp ipa-ods-exporter[16288]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:21:41 hn-dlp ipa-ods-exporter[16288]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:21:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:21:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:22:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:22:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:22:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 629. Jan 10 06:22:42 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:22:42 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:22:44 hn-dlp platform-python[16298]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:22:44 hn-dlp platform-python[16298]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:22:44 hn-dlp platform-python[16298]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:22:45 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16298]: new replica keys in LDAP: set() Jan 10 06:22:45 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16298]: obsolete replica keys in local HSM: set() Jan 10 06:22:45 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16298]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:22:45 hn-dlp ipa-ods-exporter[16298]: Traceback (most recent call last): Jan 10 06:22:45 hn-dlp ipa-ods-exporter[16298]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:22:45 hn-dlp ipa-ods-exporter[16298]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:22:45 hn-dlp ipa-ods-exporter[16298]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:22:45 hn-dlp ipa-ods-exporter[16298]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:22:45 hn-dlp ipa-ods-exporter[16298]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:22:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:22:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:23:18 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:23:18 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:23:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:23:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 630. Jan 10 06:23:45 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:23:45 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:23:47 hn-dlp platform-python[16308]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:23:47 hn-dlp platform-python[16308]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:23:47 hn-dlp platform-python[16308]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:23:48 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16308]: new replica keys in LDAP: set() Jan 10 06:23:48 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16308]: obsolete replica keys in local HSM: set() Jan 10 06:23:48 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16308]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 06:23:48 hn-dlp ipa-ods-exporter[16308]: Traceback (most recent call last): Jan 10 06:23:48 hn-dlp ipa-ods-exporter[16308]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:23:48 hn-dlp ipa-ods-exporter[16308]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:23:48 hn-dlp ipa-ods-exporter[16308]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:23:48 hn-dlp ipa-ods-exporter[16308]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:23:48 hn-dlp ipa-ods-exporter[16308]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:23:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:23:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:24:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:24:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:24:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 631. Jan 10 06:24:48 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:24:48 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:24:51 hn-dlp platform-python[16317]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:24:51 hn-dlp platform-python[16317]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:24:51 hn-dlp platform-python[16317]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:24:51 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16317]: new replica keys in LDAP: set() Jan 10 06:24:51 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16317]: obsolete replica keys in local HSM: set() Jan 10 06:24:51 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16317]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:24:51 hn-dlp ipa-ods-exporter[16317]: Traceback (most recent call last): Jan 10 06:24:51 hn-dlp ipa-ods-exporter[16317]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:24:51 hn-dlp ipa-ods-exporter[16317]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:24:51 hn-dlp ipa-ods-exporter[16317]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:24:51 hn-dlp ipa-ods-exporter[16317]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:24:51 hn-dlp ipa-ods-exporter[16317]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:24:51 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:24:51 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:25:18 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 06:25:18 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:25:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:25:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 632. Jan 10 06:25:52 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:25:52 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:25:54 hn-dlp platform-python[16326]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:25:54 hn-dlp platform-python[16326]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:25:54 hn-dlp platform-python[16326]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:25:54 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16326]: new replica keys in LDAP: set() Jan 10 06:25:54 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16326]: obsolete replica keys in local HSM: set() Jan 10 06:25:54 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16326]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:25:54 hn-dlp ipa-ods-exporter[16326]: Traceback (most recent call last): Jan 10 06:25:54 hn-dlp ipa-ods-exporter[16326]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:25:54 hn-dlp ipa-ods-exporter[16326]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:25:54 hn-dlp ipa-ods-exporter[16326]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:25:54 hn-dlp ipa-ods-exporter[16326]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:25:54 hn-dlp ipa-ods-exporter[16326]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:25:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:25:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:26:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:26:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:26:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 633. Jan 10 06:26:55 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:26:55 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:26:57 hn-dlp platform-python[16336]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:26:57 hn-dlp platform-python[16336]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:26:57 hn-dlp platform-python[16336]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:26:58 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16336]: new replica keys in LDAP: set() Jan 10 06:26:58 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16336]: obsolete replica keys in local HSM: set() Jan 10 06:26:58 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16336]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:26:58 hn-dlp ipa-ods-exporter[16336]: Traceback (most recent call last): Jan 10 06:26:58 hn-dlp ipa-ods-exporter[16336]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:26:58 hn-dlp ipa-ods-exporter[16336]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:26:58 hn-dlp ipa-ods-exporter[16336]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:26:58 hn-dlp ipa-ods-exporter[16336]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:26:58 hn-dlp ipa-ods-exporter[16336]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:26:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:26:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:27:18 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:27:18 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:27:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:27:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 634. Jan 10 06:27:58 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:27:58 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:28:01 hn-dlp platform-python[16344]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:28:01 hn-dlp platform-python[16344]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:28:01 hn-dlp platform-python[16344]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:28:01 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16344]: new replica keys in LDAP: set() Jan 10 06:28:01 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16344]: obsolete replica keys in local HSM: set() Jan 10 06:28:01 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16344]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 06:28:01 hn-dlp ipa-ods-exporter[16344]: Traceback (most recent call last): Jan 10 06:28:01 hn-dlp ipa-ods-exporter[16344]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:28:01 hn-dlp ipa-ods-exporter[16344]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:28:01 hn-dlp ipa-ods-exporter[16344]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:28:01 hn-dlp ipa-ods-exporter[16344]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:28:01 hn-dlp ipa-ods-exporter[16344]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:28:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:28:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:28:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:28:51 hn-dlp systemd[1]: Starting dnf makecache... Jan 10 06:28:52 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.131' (uid=0 pid=669 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 06:28:52 hn-dlp dbus-daemon[16402]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 06:28:53 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 06:28:54 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.1156' (uid=995 pid=16402 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 06:28:54 hn-dlp dbus-daemon[16416]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 06:28:54 hn-dlp dnf[16400]: Updating Subscription Management repositories. Jan 10 06:28:55 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 06:28:59 hn-dlp setroubleshoot[16402]: SELinux is preventing /usr/libexec/platform-python3.6 from getattr access on the file /usr/sbin/kpatch. For complete SELinux messages run: sealert -l 5cda8d58-1349-4feb-8b4b-5d3fe096a952 Jan 10 06:28:59 hn-dlp setroubleshoot[16402]: SELinux is preventing /usr/libexec/platform-python3.6 from getattr access on the file /usr/sbin/kpatch.#012#012***** Plugin catchall (100. confidence) suggests **************************#012#012If you believe that platform-python3.6 should be allowed getattr access on the kpatch file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'rhsmcertd-worke' --raw | audit2allow -M my-rhsmcertdworke#012# semodule -X 300 -i my-rhsmcertdworke.pp#012 Jan 10 06:29:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:29:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 635. Jan 10 06:29:02 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:29:02 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:29:06 hn-dlp setroubleshoot[16402]: SELinux is preventing rhsmcertd-worke from execute access on the file kpatch. For complete SELinux messages run: sealert -l 684ea0a4-d817-4204-9a20-c69257d26cfb Jan 10 06:29:06 hn-dlp setroubleshoot[16402]: SELinux is preventing rhsmcertd-worke from execute access on the file kpatch.#012#012***** Plugin catchall (100. confidence) suggests **************************#012#012If you believe that rhsmcertd-worke should be allowed execute access on the kpatch file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'rhsmcertd-worke' --raw | audit2allow -M my-rhsmcertdworke#012# semodule -X 300 -i my-rhsmcertdworke.pp#012 Jan 10 06:29:17 hn-dlp platform-python[16422]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:29:17 hn-dlp platform-python[16422]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:29:17 hn-dlp platform-python[16422]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:29:18 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16422]: new replica keys in LDAP: set() Jan 10 06:29:18 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16422]: obsolete replica keys in local HSM: set() Jan 10 06:29:18 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16422]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:29:18 hn-dlp ipa-ods-exporter[16422]: Traceback (most recent call last): Jan 10 06:29:18 hn-dlp ipa-ods-exporter[16422]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:29:18 hn-dlp ipa-ods-exporter[16422]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:29:18 hn-dlp ipa-ods-exporter[16422]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:29:18 hn-dlp ipa-ods-exporter[16422]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:29:18 hn-dlp ipa-ods-exporter[16422]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:29:18 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:29:18 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:29:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:29:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:29:18 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.131' (uid=0 pid=669 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 06:29:18 hn-dlp dbus-daemon[16449]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 06:29:21 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 06:29:21 hn-dlp dnf[16400]: CentOS Linux 8 - AppStream 10 kB/s | 4.3 kB 00:00 Jan 10 06:29:22 hn-dlp dnf[16400]: CentOS Linux 8 - BaseOS 10 kB/s | 3.9 kB 00:00 Jan 10 06:29:22 hn-dlp dbus-daemon[702]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.1163' (uid=995 pid=16449 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 06:29:22 hn-dlp dbus-daemon[16468]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 06:29:22 hn-dlp dnf[16400]: CentOS Linux 8 - Extras 30 kB/s | 1.5 kB 00:00 Jan 10 06:29:22 hn-dlp dnf[16400]: Tecin Centos 8 puppetCrlUpdater 21 kB/s | 3.4 kB 00:00 Jan 10 06:29:22 hn-dlp dnf[16400]: Rspamd8 20 kB/s | 3.5 kB 00:00 Jan 10 06:29:22 hn-dlp dbus-daemon[702]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 06:29:23 hn-dlp dnf[16400]: Puppet8 20 kB/s | 3.5 kB 00:00 Jan 10 06:29:23 hn-dlp dnf[16400]: CentOS 8 BaseOS 23 kB/s | 3.8 kB 00:00 Jan 10 06:29:23 hn-dlp dnf[16400]: Client8 23 kB/s | 3.7 kB 00:00 Jan 10 06:29:23 hn-dlp dnf[16400]: Tecin Centos 8 puppetMasterCrlUpdater 21 kB/s | 3.4 kB 00:00 Jan 10 06:29:23 hn-dlp dnf[16400]: CentOS 8 Extras 18 kB/s | 3.5 kB 00:00 Jan 10 06:29:23 hn-dlp dnf[16400]: CentOS 8 AppStream 25 kB/s | 4.1 kB 00:00 Jan 10 06:29:24 hn-dlp dnf[16400]: EPEL8 25 kB/s | 4.3 kB 00:00 Jan 10 06:29:24 hn-dlp dnf[16400]: Client8 22 kB/s | 3.5 kB 00:00 Jan 10 06:29:24 hn-dlp dnf[16400]: CentOS 8 PowerTools 24 kB/s | 4.1 kB 00:00 Jan 10 06:29:24 hn-dlp dnf[16400]: CentOS 8 CentOSPlus 19 kB/s | 3.5 kB 00:00 Jan 10 06:29:25 hn-dlp dnf[16400]: Client8-non-supported 20 kB/s | 3.4 kB 00:00 Jan 10 06:29:25 hn-dlp dnf[16400]: Tecin Centos 8 certmongerPuppetSelinuxPolicy 20 kB/s | 3.4 kB 00:00 Jan 10 06:29:25 hn-dlp setroubleshoot[16449]: SELinux is preventing rhsmcertd-worke from read access on the file container-tools.module. For complete SELinux messages run: sealert -l bb37e6ed-51d9-407e-8b19-3b95ed2f0fd2 Jan 10 06:29:25 hn-dlp setroubleshoot[16449]: SELinux is preventing rhsmcertd-worke from read access on the file container-tools.module.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow daemons to dump core#012Then you must tell SELinux about this by enabling the 'daemons_dump_core' boolean.#012#012Do#012setsebool -P daemons_dump_core 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that rhsmcertd-worke should be allowed read access on the container-tools.module file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'rhsmcertd-worke' --raw | audit2allow -M my-rhsmcertdworke#012# semodule -X 300 -i my-rhsmcertdworke.pp#012 Jan 10 06:29:26 hn-dlp setroubleshoot[16449]: SELinux is preventing rhsmcertd-worke from read access on the file container-tools.module. For complete SELinux messages run: sealert -l bb37e6ed-51d9-407e-8b19-3b95ed2f0fd2 Jan 10 06:29:26 hn-dlp setroubleshoot[16449]: SELinux is preventing rhsmcertd-worke from read access on the file container-tools.module.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow daemons to dump core#012Then you must tell SELinux about this by enabling the 'daemons_dump_core' boolean.#012#012Do#012setsebool -P daemons_dump_core 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that rhsmcertd-worke should be allowed read access on the container-tools.module file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'rhsmcertd-worke' --raw | audit2allow -M my-rhsmcertdworke#012# semodule -X 300 -i my-rhsmcertdworke.pp#012 Jan 10 06:29:26 hn-dlp dnf[16400]: Metadata cache created. Jan 10 06:29:26 hn-dlp systemd[1]: dnf-makecache.service: Succeeded. Jan 10 06:29:26 hn-dlp systemd[1]: Started dnf makecache. Jan 10 06:30:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:30:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:30:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 636. Jan 10 06:30:18 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:30:18 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:30:23 hn-dlp platform-python[16494]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:30:23 hn-dlp platform-python[16494]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:30:23 hn-dlp platform-python[16494]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:30:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16494]: new replica keys in LDAP: set() Jan 10 06:30:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16494]: obsolete replica keys in local HSM: set() Jan 10 06:30:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16494]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:30:23 hn-dlp ipa-ods-exporter[16494]: Traceback (most recent call last): Jan 10 06:30:23 hn-dlp ipa-ods-exporter[16494]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:30:23 hn-dlp ipa-ods-exporter[16494]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:30:23 hn-dlp ipa-ods-exporter[16494]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:30:23 hn-dlp ipa-ods-exporter[16494]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:30:23 hn-dlp ipa-ods-exporter[16494]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:30:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:30:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:30:38 hn-dlp systemd[1]: Created slice User Slice of UID 2002. Jan 10 06:30:38 hn-dlp systemd[1]: Started /run/user/2002 mount wrapper. Jan 10 06:30:38 hn-dlp systemd[1]: Starting User Manager for UID 2002... Jan 10 06:30:38 hn-dlp systemd-logind[736]: New session 48 of user svcforeman. Jan 10 06:30:38 hn-dlp systemd[1]: Started Session 48 of user svcforeman. Jan 10 06:30:38 hn-dlp systemd[16509]: Starting D-Bus User Message Bus Socket. Jan 10 06:30:38 hn-dlp systemd[16509]: Started Mark boot as successful after the user session has run 2 minutes. Jan 10 06:30:38 hn-dlp systemd[16509]: Reached target Paths. Jan 10 06:30:38 hn-dlp systemd[16509]: Reached target Timers. Jan 10 06:30:38 hn-dlp systemd[16509]: Listening on D-Bus User Message Bus Socket. Jan 10 06:30:38 hn-dlp systemd[16509]: Reached target Sockets. Jan 10 06:30:38 hn-dlp systemd[16509]: Reached target Basic System. Jan 10 06:30:38 hn-dlp systemd[16509]: Reached target Default. Jan 10 06:30:38 hn-dlp systemd[16509]: Startup finished in 151ms. Jan 10 06:30:38 hn-dlp systemd[1]: Started User Manager for UID 2002. Jan 10 06:30:40 hn-dlp platform-python[16671]: ansible-setup Invoked with gather_timeout=10 gather_subset=['all'] filter=* fact_path=/etc/ansible/facts.d Jan 10 06:31:19 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:31:19 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:31:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:31:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 637. Jan 10 06:31:23 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:31:23 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:31:26 hn-dlp platform-python[16778]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:31:26 hn-dlp platform-python[16778]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:31:26 hn-dlp platform-python[16778]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:31:26 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16778]: new replica keys in LDAP: set() Jan 10 06:31:26 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16778]: obsolete replica keys in local HSM: set() Jan 10 06:31:26 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16778]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 06:31:26 hn-dlp ipa-ods-exporter[16778]: Traceback (most recent call last): Jan 10 06:31:26 hn-dlp ipa-ods-exporter[16778]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:31:26 hn-dlp ipa-ods-exporter[16778]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:31:26 hn-dlp ipa-ods-exporter[16778]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:31:26 hn-dlp ipa-ods-exporter[16778]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:31:26 hn-dlp ipa-ods-exporter[16778]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:31:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:31:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:31:47 hn-dlp systemd[1]: session-48.scope: Succeeded. Jan 10 06:31:47 hn-dlp systemd-logind[736]: Session 48 logged out. Waiting for processes to exit. Jan 10 06:31:47 hn-dlp systemd-logind[736]: Removed session 48. Jan 10 06:31:47 hn-dlp systemd[1]: Stopping User Manager for UID 2002... Jan 10 06:31:47 hn-dlp systemd[16509]: Stopped target Default. Jan 10 06:31:47 hn-dlp systemd[16509]: Stopped target Basic System. Jan 10 06:31:47 hn-dlp systemd[16509]: Stopped target Paths. Jan 10 06:31:47 hn-dlp systemd[16509]: Stopped target Sockets. Jan 10 06:31:47 hn-dlp systemd[16509]: dbus.socket: Succeeded. Jan 10 06:31:47 hn-dlp systemd[16509]: Closed D-Bus User Message Bus Socket. Jan 10 06:31:47 hn-dlp systemd[16509]: Stopped target Timers. Jan 10 06:31:47 hn-dlp systemd[16509]: grub-boot-success.timer: Succeeded. Jan 10 06:31:47 hn-dlp systemd[16509]: Stopped Mark boot as successful after the user session has run 2 minutes. Jan 10 06:31:47 hn-dlp systemd[16509]: Reached target Shutdown. Jan 10 06:31:47 hn-dlp systemd[16509]: Starting Exit the Session... Jan 10 06:31:47 hn-dlp systemd[1]: user@2002.service: Succeeded. Jan 10 06:31:47 hn-dlp systemd[1]: Stopped User Manager for UID 2002. Jan 10 06:31:47 hn-dlp systemd[1]: Stopping /run/user/2002 mount wrapper... Jan 10 06:31:47 hn-dlp systemd[1]: Removed slice User Slice of UID 2002. Jan 10 06:31:47 hn-dlp systemd[1]: run-user-2002.mount: Succeeded. Jan 10 06:31:47 hn-dlp systemd[1]: user-runtime-dir@2002.service: Succeeded. Jan 10 06:31:47 hn-dlp systemd[1]: Stopped /run/user/2002 mount wrapper. Jan 10 06:32:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:32:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:32:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 638. Jan 10 06:32:27 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:32:27 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:32:29 hn-dlp platform-python[16796]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:32:29 hn-dlp platform-python[16796]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:32:29 hn-dlp platform-python[16796]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:32:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16796]: new replica keys in LDAP: set() Jan 10 06:32:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16796]: obsolete replica keys in local HSM: set() Jan 10 06:32:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16796]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:32:30 hn-dlp ipa-ods-exporter[16796]: Traceback (most recent call last): Jan 10 06:32:30 hn-dlp ipa-ods-exporter[16796]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:32:30 hn-dlp ipa-ods-exporter[16796]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:32:30 hn-dlp ipa-ods-exporter[16796]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:32:30 hn-dlp ipa-ods-exporter[16796]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:32:30 hn-dlp ipa-ods-exporter[16796]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:32:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:32:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:33:19 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:33:19 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:33:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:33:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 639. Jan 10 06:33:30 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:33:30 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:33:32 hn-dlp platform-python[16804]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:33:32 hn-dlp platform-python[16804]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:33:32 hn-dlp platform-python[16804]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:33:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16804]: new replica keys in LDAP: set() Jan 10 06:33:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16804]: obsolete replica keys in local HSM: set() Jan 10 06:33:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16804]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:33:33 hn-dlp ipa-ods-exporter[16804]: Traceback (most recent call last): Jan 10 06:33:33 hn-dlp ipa-ods-exporter[16804]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:33:33 hn-dlp ipa-ods-exporter[16804]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:33:33 hn-dlp ipa-ods-exporter[16804]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:33:33 hn-dlp ipa-ods-exporter[16804]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:33:33 hn-dlp ipa-ods-exporter[16804]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:33:33 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:33:33 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:34:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:34:33 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:34:33 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 640. Jan 10 06:34:33 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:34:33 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:34:36 hn-dlp platform-python[16818]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:34:36 hn-dlp platform-python[16818]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:34:36 hn-dlp platform-python[16818]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:34:36 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16818]: new replica keys in LDAP: set() Jan 10 06:34:36 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16818]: obsolete replica keys in local HSM: set() Jan 10 06:34:36 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16818]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:34:36 hn-dlp ipa-ods-exporter[16818]: Traceback (most recent call last): Jan 10 06:34:36 hn-dlp ipa-ods-exporter[16818]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:34:36 hn-dlp ipa-ods-exporter[16818]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:34:36 hn-dlp ipa-ods-exporter[16818]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:34:36 hn-dlp ipa-ods-exporter[16818]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:34:36 hn-dlp ipa-ods-exporter[16818]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:34:36 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:34:36 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:35:20 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 06:35:20 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:35:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:35:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 641. Jan 10 06:35:37 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:35:37 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:35:39 hn-dlp platform-python[16828]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:35:39 hn-dlp platform-python[16828]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:35:39 hn-dlp platform-python[16828]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:35:39 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16828]: new replica keys in LDAP: set() Jan 10 06:35:39 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16828]: obsolete replica keys in local HSM: set() Jan 10 06:35:39 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16828]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 06:35:39 hn-dlp ipa-ods-exporter[16828]: Traceback (most recent call last): Jan 10 06:35:39 hn-dlp ipa-ods-exporter[16828]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:35:39 hn-dlp ipa-ods-exporter[16828]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:35:39 hn-dlp ipa-ods-exporter[16828]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:35:39 hn-dlp ipa-ods-exporter[16828]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:35:39 hn-dlp ipa-ods-exporter[16828]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:35:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:35:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:36:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:36:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:36:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 642. Jan 10 06:36:40 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:36:40 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:36:42 hn-dlp platform-python[16836]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:36:42 hn-dlp platform-python[16836]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:36:42 hn-dlp platform-python[16836]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:36:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16836]: new replica keys in LDAP: set() Jan 10 06:36:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16836]: obsolete replica keys in local HSM: set() Jan 10 06:36:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16836]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:36:43 hn-dlp ipa-ods-exporter[16836]: Traceback (most recent call last): Jan 10 06:36:43 hn-dlp ipa-ods-exporter[16836]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:36:43 hn-dlp ipa-ods-exporter[16836]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:36:43 hn-dlp ipa-ods-exporter[16836]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:36:43 hn-dlp ipa-ods-exporter[16836]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:36:43 hn-dlp ipa-ods-exporter[16836]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:36:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:36:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:37:20 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:37:20 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:37:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:37:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 643. Jan 10 06:37:43 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:37:43 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:37:45 hn-dlp platform-python[16845]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:37:45 hn-dlp platform-python[16845]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:37:45 hn-dlp platform-python[16845]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:37:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16845]: new replica keys in LDAP: set() Jan 10 06:37:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16845]: obsolete replica keys in local HSM: set() Jan 10 06:37:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16845]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:37:46 hn-dlp ipa-ods-exporter[16845]: Traceback (most recent call last): Jan 10 06:37:46 hn-dlp ipa-ods-exporter[16845]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:37:46 hn-dlp ipa-ods-exporter[16845]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:37:46 hn-dlp ipa-ods-exporter[16845]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:37:46 hn-dlp ipa-ods-exporter[16845]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:37:46 hn-dlp ipa-ods-exporter[16845]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:37:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:37:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:38:18 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:38:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:38:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 644. Jan 10 06:38:46 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:38:46 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:38:49 hn-dlp platform-python[16853]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:38:49 hn-dlp platform-python[16853]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:38:49 hn-dlp platform-python[16853]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:38:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16853]: new replica keys in LDAP: set() Jan 10 06:38:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16853]: obsolete replica keys in local HSM: set() Jan 10 06:38:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16853]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:38:49 hn-dlp ipa-ods-exporter[16853]: Traceback (most recent call last): Jan 10 06:38:49 hn-dlp ipa-ods-exporter[16853]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:38:49 hn-dlp ipa-ods-exporter[16853]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:38:49 hn-dlp ipa-ods-exporter[16853]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:38:49 hn-dlp ipa-ods-exporter[16853]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:38:49 hn-dlp ipa-ods-exporter[16853]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:38:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:38:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:39:20 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:39:20 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:39:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:39:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 645. Jan 10 06:39:49 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:39:49 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:39:52 hn-dlp platform-python[16863]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:39:52 hn-dlp platform-python[16863]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:39:52 hn-dlp platform-python[16863]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:39:52 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16863]: new replica keys in LDAP: set() Jan 10 06:39:52 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16863]: obsolete replica keys in local HSM: set() Jan 10 06:39:52 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16863]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:39:52 hn-dlp ipa-ods-exporter[16863]: Traceback (most recent call last): Jan 10 06:39:52 hn-dlp ipa-ods-exporter[16863]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:39:52 hn-dlp ipa-ods-exporter[16863]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:39:52 hn-dlp ipa-ods-exporter[16863]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:39:52 hn-dlp ipa-ods-exporter[16863]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:39:52 hn-dlp ipa-ods-exporter[16863]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:39:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:39:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:40:19 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:40:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:40:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 646. Jan 10 06:40:53 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:40:53 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:40:55 hn-dlp platform-python[16873]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:40:55 hn-dlp platform-python[16873]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:40:55 hn-dlp platform-python[16873]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:40:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16873]: new replica keys in LDAP: set() Jan 10 06:40:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16873]: obsolete replica keys in local HSM: set() Jan 10 06:40:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16873]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:40:55 hn-dlp ipa-ods-exporter[16873]: Traceback (most recent call last): Jan 10 06:40:55 hn-dlp ipa-ods-exporter[16873]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:40:55 hn-dlp ipa-ods-exporter[16873]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:40:55 hn-dlp ipa-ods-exporter[16873]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:40:55 hn-dlp ipa-ods-exporter[16873]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:40:55 hn-dlp ipa-ods-exporter[16873]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:40:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:40:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:41:20 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:41:20 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:41:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:41:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 647. Jan 10 06:41:56 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:41:56 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:41:58 hn-dlp platform-python[16882]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:41:58 hn-dlp platform-python[16882]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:41:58 hn-dlp platform-python[16882]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:41:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16882]: new replica keys in LDAP: set() Jan 10 06:41:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16882]: obsolete replica keys in local HSM: set() Jan 10 06:41:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16882]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 06:41:59 hn-dlp ipa-ods-exporter[16882]: Traceback (most recent call last): Jan 10 06:41:59 hn-dlp ipa-ods-exporter[16882]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:41:59 hn-dlp ipa-ods-exporter[16882]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:41:59 hn-dlp ipa-ods-exporter[16882]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:41:59 hn-dlp ipa-ods-exporter[16882]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:41:59 hn-dlp ipa-ods-exporter[16882]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:41:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:41:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:42:19 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:42:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:42:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 648. Jan 10 06:42:59 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:42:59 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:43:01 hn-dlp platform-python[16891]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:43:01 hn-dlp platform-python[16891]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:43:01 hn-dlp platform-python[16891]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:43:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16891]: new replica keys in LDAP: set() Jan 10 06:43:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16891]: obsolete replica keys in local HSM: set() Jan 10 06:43:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16891]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 06:43:02 hn-dlp ipa-ods-exporter[16891]: Traceback (most recent call last): Jan 10 06:43:02 hn-dlp ipa-ods-exporter[16891]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:43:02 hn-dlp ipa-ods-exporter[16891]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:43:02 hn-dlp ipa-ods-exporter[16891]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:43:02 hn-dlp ipa-ods-exporter[16891]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:43:02 hn-dlp ipa-ods-exporter[16891]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:43:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:43:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:43:20 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:43:20 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:44:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:44:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 649. Jan 10 06:44:02 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:44:02 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:44:05 hn-dlp platform-python[16900]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:44:05 hn-dlp platform-python[16900]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:44:05 hn-dlp platform-python[16900]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:44:05 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16900]: new replica keys in LDAP: set() Jan 10 06:44:05 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16900]: obsolete replica keys in local HSM: set() Jan 10 06:44:05 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16900]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 06:44:05 hn-dlp ipa-ods-exporter[16900]: Traceback (most recent call last): Jan 10 06:44:05 hn-dlp ipa-ods-exporter[16900]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:44:05 hn-dlp ipa-ods-exporter[16900]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:44:05 hn-dlp ipa-ods-exporter[16900]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:44:05 hn-dlp ipa-ods-exporter[16900]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:44:05 hn-dlp ipa-ods-exporter[16900]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:44:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:44:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:44:19 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:45:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:45:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 650. Jan 10 06:45:05 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:45:05 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:45:08 hn-dlp platform-python[16908]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:45:08 hn-dlp platform-python[16908]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:45:08 hn-dlp platform-python[16908]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:45:08 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16908]: new replica keys in LDAP: set() Jan 10 06:45:08 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16908]: obsolete replica keys in local HSM: set() Jan 10 06:45:08 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16908]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:45:08 hn-dlp ipa-ods-exporter[16908]: Traceback (most recent call last): Jan 10 06:45:08 hn-dlp ipa-ods-exporter[16908]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:45:08 hn-dlp ipa-ods-exporter[16908]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:45:08 hn-dlp ipa-ods-exporter[16908]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:45:08 hn-dlp ipa-ods-exporter[16908]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:45:08 hn-dlp ipa-ods-exporter[16908]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:45:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:45:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:45:20 hn-dlp named-pkcs11[1516]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 06:45:20 hn-dlp named-pkcs11[1516]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:46:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:46:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 651. Jan 10 06:46:08 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:46:08 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:46:11 hn-dlp platform-python[16919]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:46:11 hn-dlp platform-python[16919]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:46:11 hn-dlp platform-python[16919]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:46:11 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16919]: new replica keys in LDAP: set() Jan 10 06:46:11 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16919]: obsolete replica keys in local HSM: set() Jan 10 06:46:11 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16919]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 06:46:11 hn-dlp ipa-ods-exporter[16919]: Traceback (most recent call last): Jan 10 06:46:11 hn-dlp ipa-ods-exporter[16919]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:46:11 hn-dlp ipa-ods-exporter[16919]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:46:11 hn-dlp ipa-ods-exporter[16919]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:46:11 hn-dlp ipa-ods-exporter[16919]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:46:11 hn-dlp ipa-ods-exporter[16919]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:46:11 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:46:11 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:46:19 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:47:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:47:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 652. Jan 10 06:47:12 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:47:12 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:47:14 hn-dlp platform-python[16928]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:47:14 hn-dlp platform-python[16928]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:47:14 hn-dlp platform-python[16928]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:47:14 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16928]: new replica keys in LDAP: set() Jan 10 06:47:14 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16928]: obsolete replica keys in local HSM: set() Jan 10 06:47:14 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16928]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 06:47:14 hn-dlp ipa-ods-exporter[16928]: Traceback (most recent call last): Jan 10 06:47:14 hn-dlp ipa-ods-exporter[16928]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:47:14 hn-dlp ipa-ods-exporter[16928]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:47:14 hn-dlp ipa-ods-exporter[16928]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:47:14 hn-dlp ipa-ods-exporter[16928]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:47:14 hn-dlp ipa-ods-exporter[16928]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:47:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:47:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:47:21 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:47:21 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:48:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:48:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 653. Jan 10 06:48:15 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:48:15 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:48:17 hn-dlp platform-python[16937]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:48:17 hn-dlp platform-python[16937]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:48:17 hn-dlp platform-python[16937]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:48:18 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16937]: new replica keys in LDAP: set() Jan 10 06:48:18 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16937]: obsolete replica keys in local HSM: set() Jan 10 06:48:18 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16937]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:48:18 hn-dlp ipa-ods-exporter[16937]: Traceback (most recent call last): Jan 10 06:48:18 hn-dlp ipa-ods-exporter[16937]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:48:18 hn-dlp ipa-ods-exporter[16937]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:48:18 hn-dlp ipa-ods-exporter[16937]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:48:18 hn-dlp ipa-ods-exporter[16937]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:48:18 hn-dlp ipa-ods-exporter[16937]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:48:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:48:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:48:19 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:49:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:49:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 654. Jan 10 06:49:18 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:49:18 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:49:20 hn-dlp platform-python[16949]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:49:20 hn-dlp platform-python[16949]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:49:20 hn-dlp platform-python[16949]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:49:21 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:49:21 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:49:21 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16949]: new replica keys in LDAP: set() Jan 10 06:49:21 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16949]: obsolete replica keys in local HSM: set() Jan 10 06:49:21 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16949]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 06:49:21 hn-dlp ipa-ods-exporter[16949]: Traceback (most recent call last): Jan 10 06:49:21 hn-dlp ipa-ods-exporter[16949]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:49:21 hn-dlp ipa-ods-exporter[16949]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:49:21 hn-dlp ipa-ods-exporter[16949]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:49:21 hn-dlp ipa-ods-exporter[16949]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:49:21 hn-dlp ipa-ods-exporter[16949]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:49:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:49:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:50:19 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:50:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:50:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 655. Jan 10 06:50:21 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:50:21 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:50:24 hn-dlp platform-python[16961]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:50:24 hn-dlp platform-python[16961]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:50:24 hn-dlp platform-python[16961]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:50:24 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16961]: new replica keys in LDAP: set() Jan 10 06:50:24 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16961]: obsolete replica keys in local HSM: set() Jan 10 06:50:24 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16961]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:50:24 hn-dlp ipa-ods-exporter[16961]: Traceback (most recent call last): Jan 10 06:50:24 hn-dlp ipa-ods-exporter[16961]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:50:24 hn-dlp ipa-ods-exporter[16961]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:50:24 hn-dlp ipa-ods-exporter[16961]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:50:24 hn-dlp ipa-ods-exporter[16961]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:50:24 hn-dlp ipa-ods-exporter[16961]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:50:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:50:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:51:21 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:51:21 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:51:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:51:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 656. Jan 10 06:51:24 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:51:24 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:51:27 hn-dlp platform-python[16973]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:51:27 hn-dlp platform-python[16973]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:51:27 hn-dlp platform-python[16973]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:51:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16973]: new replica keys in LDAP: set() Jan 10 06:51:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16973]: obsolete replica keys in local HSM: set() Jan 10 06:51:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16973]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:51:27 hn-dlp ipa-ods-exporter[16973]: Traceback (most recent call last): Jan 10 06:51:27 hn-dlp ipa-ods-exporter[16973]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:51:27 hn-dlp ipa-ods-exporter[16973]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:51:27 hn-dlp ipa-ods-exporter[16973]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:51:27 hn-dlp ipa-ods-exporter[16973]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:51:27 hn-dlp ipa-ods-exporter[16973]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:51:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:51:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:52:19 hn-dlp puppet-agent[762]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 06:52:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:52:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 657. Jan 10 06:52:27 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:52:27 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:52:30 hn-dlp platform-python[16982]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:52:30 hn-dlp platform-python[16982]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:52:30 hn-dlp platform-python[16982]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:52:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16982]: new replica keys in LDAP: set() Jan 10 06:52:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16982]: obsolete replica keys in local HSM: set() Jan 10 06:52:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16982]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 06:52:30 hn-dlp ipa-ods-exporter[16982]: Traceback (most recent call last): Jan 10 06:52:30 hn-dlp ipa-ods-exporter[16982]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:52:30 hn-dlp ipa-ods-exporter[16982]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:52:30 hn-dlp ipa-ods-exporter[16982]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:52:30 hn-dlp ipa-ods-exporter[16982]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:52:30 hn-dlp ipa-ods-exporter[16982]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:52:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:52:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:53:22 hn-dlp named-pkcs11[1516]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 06:53:22 hn-dlp named-pkcs11[1516]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 06:53:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 06:53:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 658. Jan 10 06:53:31 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:53:31 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 06:53:33 hn-dlp platform-python[16989]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 06:53:33 hn-dlp platform-python[16989]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 06:53:33 hn-dlp platform-python[16989]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 06:53:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16989]: new replica keys in LDAP: set() Jan 10 06:53:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16989]: obsolete replica keys in local HSM: set() Jan 10 06:53:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[16989]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 06:53:33 hn-dlp ipa-ods-exporter[16989]: Traceback (most recent call last): Jan 10 06:53:33 hn-dlp ipa-ods-exporter[16989]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 06:53:33 hn-dlp ipa-ods-exporter[16989]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 06:53:33 hn-dlp ipa-ods-exporter[16989]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 06:53:33 hn-dlp ipa-ods-exporter[16989]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 06:53:33 hn-dlp ipa-ods-exporter[16989]: KeyError: 'popitem(): dictionary is empty' Jan 10 06:53:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 06:53:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 06:54:05 hn-dlp systemd[1]: Started /run/user/0 mount wrapper. Jan 10 06:54:05 hn-dlp systemd[1]: Created slice User Slice of UID 0. Jan 10 06:54:05 hn-dlp systemd[1]: Starting User Manager for UID 0... Jan 10 06:54:05 hn-dlp systemd-logind[736]: New session 50 of user root. Jan 10 06:54:05 hn-dlp systemd[1]: Started Session 50 of user root. Jan 10 06:54:05 hn-dlp systemd[17004]: Starting D-Bus User Message Bus Socket. Jan 10 06:54:05 hn-dlp systemd[17004]: Reached target Paths. Jan 10 06:54:05 hn-dlp systemd[17004]: Reached target Timers. Jan 10 06:54:05 hn-dlp systemd[17004]: Listening on D-Bus User Message Bus Socket. Jan 10 06:54:05 hn-dlp systemd[17004]: Reached target Sockets. Jan 10 06:54:05 hn-dlp systemd[17004]: Reached target Basic System. Jan 10 06:54:05 hn-dlp systemd[17004]: Reached target Default. Jan 10 06:54:05 hn-dlp systemd[17004]: Startup finished in 48ms. Jan 10 06:54:05 hn-dlp systemd[1]: Started User Manager for UID 0. Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Session 50 of user root. Jan 10 06:54:14 hn-dlp systemd[1]: Stopping OpenDNSSEC Enforcer daemon... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Kerberos 5 Password-changing and Administration... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Kerberos 5 KDC... Jan 10 06:54:14 hn-dlp systemd[1]: Removed slice system-systemd\x2dhibernate\x2dresume.slice. Jan 10 06:54:14 hn-dlp systemd[1]: Stopping The Apache HTTP Server... Jan 10 06:54:14 hn-dlp systemd[1]: Stopped target PKI Tomcat Server. Jan 10 06:54:14 hn-dlp systemd[1]: Stopping PKI Tomcat Server pki-tomcat... Jan 10 06:54:14 hn-dlp systemd[1]: Stopped target 389 Directory Server. Jan 10 06:54:14 hn-dlp systemd[1]: Stopping User Manager for UID 0... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping 389 Directory Server IPA-TECIN-NET.... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping QEMU Guest Agent... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Hardware RNG Entropy Gatherer Daemon... Jan 10 06:54:14 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 06:54:14 hn-dlp systemd[1]: Stopped target Timers. Jan 10 06:54:14 hn-dlp systemd[1]: systemd-tmpfiles-clean.timer: Succeeded. Jan 10 06:54:14 hn-dlp systemd[1]: Stopped Daily Cleanup of Temporary Directories. Jan 10 06:54:14 hn-dlp systemd[1]: unbound-anchor.timer: Succeeded. Jan 10 06:54:14 hn-dlp systemd[1]: Stopped daily update of the root trust anchor for DNSSEC. Jan 10 06:54:14 hn-dlp systemd[1]: Stopping IPA key daemon... Jan 10 06:54:14 hn-dlp systemd[17004]: Stopped target Default. Jan 10 06:54:14 hn-dlp systemd[17004]: Stopped target Basic System. Jan 10 06:54:14 hn-dlp systemd[17004]: Stopped target Timers. Jan 10 06:54:14 hn-dlp systemd[17004]: Stopped target Paths. Jan 10 06:54:14 hn-dlp systemd[17004]: Stopped target Sockets. Jan 10 06:54:14 hn-dlp systemd[17004]: dbus.socket: Succeeded. Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Samba SMB Daemon... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping IPA Custodia Service... Jan 10 06:54:14 hn-dlp systemd[1]: lvm2-lvmpolld.socket: Succeeded. Jan 10 06:54:14 hn-dlp systemd[17004]: Closed D-Bus User Message Bus Socket. Jan 10 06:54:14 hn-dlp systemd[17004]: Reached target Shutdown. Jan 10 06:54:14 hn-dlp systemd[1]: Closed LVM2 poll daemon socket. Jan 10 06:54:14 hn-dlp systemd[1]: Stopped target Multi-User System. Jan 10 06:54:14 hn-dlp systemd[1]: Stopping libstoragemgmt plug-in server daemon... Jan 10 06:54:14 hn-dlp systemd[17004]: Starting Exit the Session... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Machine Check Exception Logging Daemon... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Certificate monitoring and PKI enrollment... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping OpenSSH server daemon... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Puppet agent... Jan 10 06:54:14 hn-dlp systemd[1]: Stopped target Login Prompts. Jan 10 06:54:14 hn-dlp systemd[1]: plymouth-quit.service: Succeeded. Jan 10 06:54:14 hn-dlp systemd[1]: Stopped Terminate Plymouth Boot Screen. Jan 10 06:54:14 hn-dlp systemd[1]: Stopping System Logging Service... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Enable periodic update of entitlement certificates.... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping VDO volume services... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Self Monitoring and Reporting Technology (SMART) Daemon... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Dynamic System Tuning Daemon... Jan 10 06:54:14 hn-dlp systemd[1]: dnf-makecache.timer: Succeeded. Jan 10 06:54:14 hn-dlp systemd[1]: Stopped dnf makecache --timer. Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Command Scheduler... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping privileged operations for unprivileged applications... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Job spooling tools... Jan 10 06:54:14 hn-dlp systemd[1]: Stopped target RPC Port Mapper. Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Restore /run/initramfs on shutdown... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Identity, Policy, Audit... Jan 10 06:54:14 hn-dlp systemd[1]: Removed slice system-sshd\x2dkeygen.slice. Jan 10 06:54:14 hn-dlp systemd[1]: Stopping irqbalance daemon... Jan 10 06:54:14 hn-dlp systemd[1]: Stopping Getty on tty1... Jan 10 06:54:14 hn-dlp systemd[1]: oddjobd.service: Succeeded. Jan 10 06:54:14 hn-dlp systemd[1]: Stopped privileged operations for unprivileged applications. Jan 10 07:52:53 hn-dlp kernel: Command line: BOOT_IMAGE=(hd0,msdos1)/vmlinuz-4.18.0-240.1.1.el8_3.x86_64 root=UUID=81811398-0853-43ac-b0da-dfc8f2c4dab8 ro crashkernel=auto resume=UUID=40a4da38-bc2d-4c40-afb2-04e76fccea50 rhgb quiet Jan 10 07:52:53 hn-dlp kernel: x86/fpu: x87 FPU will use FXSAVE Jan 10 07:52:53 hn-dlp kernel: BIOS-provided physical RAM map: Jan 10 07:52:53 hn-dlp kernel: BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable Jan 10 07:52:53 hn-dlp kernel: BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved Jan 10 07:52:53 hn-dlp kernel: BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved Jan 10 07:52:53 hn-dlp kernel: BIOS-e820: [mem 0x0000000000100000-0x000000005ffd9fff] usable Jan 10 07:52:53 hn-dlp kernel: BIOS-e820: [mem 0x000000005ffda000-0x000000005fffffff] reserved Jan 10 07:52:53 hn-dlp kernel: BIOS-e820: [mem 0x00000000feffc000-0x00000000feffffff] reserved Jan 10 07:52:53 hn-dlp kernel: BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved Jan 10 07:52:53 hn-dlp kernel: NX (Execute Disable) protection: active Jan 10 07:52:53 hn-dlp kernel: SMBIOS 2.8 present. Jan 10 07:52:53 hn-dlp kernel: DMI: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.13.0-48-gd9c812dda519-prebuilt.qemu.org 04/01/2014 Jan 10 07:52:53 hn-dlp kernel: Hypervisor detected: KVM Jan 10 07:52:53 hn-dlp kernel: kvm-clock: Using msrs 4b564d01 and 4b564d00 Jan 10 07:52:53 hn-dlp kernel: kvm-clock: cpu 0, msr 13201001, primary cpu clock Jan 10 07:52:53 hn-dlp kernel: kvm-clock: using sched offset of 9544428132 cycles Jan 10 07:52:53 hn-dlp kernel: clocksource: kvm-clock: mask: 0xffffffffffffffff max_cycles: 0x1cd42e4dffb, max_idle_ns: 881590591483 ns Jan 10 07:52:53 hn-dlp kernel: tsc: Detected 3400.024 MHz processor Jan 10 07:52:53 hn-dlp kernel: last_pfn = 0x5ffda max_arch_pfn = 0x400000000 Jan 10 07:52:53 hn-dlp kernel: x86/PAT: Configuration [0-7]: WB WC UC- UC WB WC UC- UC Jan 10 07:52:53 hn-dlp kernel: found SMP MP-table at [mem 0x000f5a80-0x000f5a8f] Jan 10 07:52:53 hn-dlp kernel: kexec: Reserving the low 1M of memory for crashkernel Jan 10 07:52:53 hn-dlp kernel: RAMDISK: [mem 0x34f0a000-0x3677cfff] Jan 10 07:52:53 hn-dlp kernel: ACPI: Early table checksum verification disabled Jan 10 07:52:53 hn-dlp kernel: ACPI: RSDP 0x00000000000F58A0 000014 (v00 BOCHS ) Jan 10 07:52:53 hn-dlp kernel: ACPI: RSDT 0x000000005FFE149B 000038 (v01 BOCHS BXPCRSDT 00000001 BXPC 00000001) Jan 10 07:52:53 hn-dlp kernel: ACPI: FACP 0x000000005FFE126D 000074 (v01 BOCHS BXPCFACP 00000001 BXPC 00000001) Jan 10 07:52:53 hn-dlp kernel: ACPI: DSDT 0x000000005FFDF040 00222D (v01 BOCHS BXPCDSDT 00000001 BXPC 00000001) Jan 10 07:52:53 hn-dlp kernel: ACPI: FACS 0x000000005FFDF000 000040 Jan 10 07:52:53 hn-dlp kernel: ACPI: APIC 0x000000005FFE12E1 000090 (v01 BOCHS BXPCAPIC 00000001 BXPC 00000001) Jan 10 07:52:53 hn-dlp kernel: ACPI: SSDT 0x000000005FFE1371 0000CA (v01 BOCHS VMGENID 00000001 BXPC 00000001) Jan 10 07:52:53 hn-dlp kernel: ACPI: HPET 0x000000005FFE143B 000038 (v01 BOCHS BXPCHPET 00000001 BXPC 00000001) Jan 10 07:52:53 hn-dlp kernel: ACPI: WAET 0x000000005FFE1473 000028 (v01 BOCHS BXPCWAET 00000001 BXPC 00000001) Jan 10 07:52:53 hn-dlp kernel: No NUMA configuration found Jan 10 07:52:53 hn-dlp kernel: Faking a node at [mem 0x0000000000000000-0x000000005ffd9fff] Jan 10 07:52:53 hn-dlp kernel: NODE_DATA(0) allocated [mem 0x5ffb0000-0x5ffd9fff] Jan 10 07:52:53 hn-dlp kernel: Using crashkernel=auto, the size chosen is a best effort estimation. Jan 10 07:52:53 hn-dlp kernel: Reserving 160MB of memory at 1360MB for crashkernel (System RAM: 1535MB) Jan 10 07:52:53 hn-dlp kernel: Zone ranges: Jan 10 07:52:53 hn-dlp kernel: DMA [mem 0x0000000000001000-0x0000000000ffffff] Jan 10 07:52:53 hn-dlp kernel: DMA32 [mem 0x0000000001000000-0x000000005ffd9fff] Jan 10 07:52:53 hn-dlp kernel: Normal empty Jan 10 07:52:53 hn-dlp kernel: Device empty Jan 10 07:52:53 hn-dlp kernel: Movable zone start for each node Jan 10 07:52:53 hn-dlp kernel: Early memory node ranges Jan 10 07:52:53 hn-dlp kernel: node 0: [mem 0x0000000000001000-0x000000000009efff] Jan 10 07:52:53 hn-dlp kernel: node 0: [mem 0x0000000000100000-0x000000005ffd9fff] Jan 10 07:52:53 hn-dlp kernel: Zeroed struct page in unavailable ranges: 136 pages Jan 10 07:52:53 hn-dlp kernel: Initmem setup node 0 [mem 0x0000000000001000-0x000000005ffd9fff] Jan 10 07:52:53 hn-dlp kernel: ACPI: PM-Timer IO Port: 0x608 Jan 10 07:52:53 hn-dlp kernel: ACPI: LAPIC_NMI (acpi_id[0xff] dfl dfl lint[0x1]) Jan 10 07:52:53 hn-dlp kernel: IOAPIC[0]: apic_id 0, version 17, address 0xfec00000, GSI 0-23 Jan 10 07:52:53 hn-dlp kernel: ACPI: INT_SRC_OVR (bus 0 bus_irq 0 global_irq 2 dfl dfl) Jan 10 07:52:53 hn-dlp kernel: ACPI: INT_SRC_OVR (bus 0 bus_irq 5 global_irq 5 high level) Jan 10 07:52:53 hn-dlp kernel: ACPI: INT_SRC_OVR (bus 0 bus_irq 9 global_irq 9 high level) Jan 10 07:52:53 hn-dlp kernel: ACPI: INT_SRC_OVR (bus 0 bus_irq 10 global_irq 10 high level) Jan 10 07:52:53 hn-dlp kernel: ACPI: INT_SRC_OVR (bus 0 bus_irq 11 global_irq 11 high level) Jan 10 07:52:53 hn-dlp kernel: Using ACPI (MADT) for SMP configuration information Jan 10 07:52:53 hn-dlp kernel: ACPI: HPET id: 0x8086a201 base: 0xfed00000 Jan 10 07:52:53 hn-dlp kernel: smpboot: Allowing 4 CPUs, 0 hotplug CPUs Jan 10 07:52:53 hn-dlp kernel: PM: Registered nosave memory: [mem 0x00000000-0x00000fff] Jan 10 07:52:53 hn-dlp kernel: PM: Registered nosave memory: [mem 0x0009f000-0x0009ffff] Jan 10 07:52:53 hn-dlp kernel: PM: Registered nosave memory: [mem 0x000a0000-0x000effff] Jan 10 07:52:53 hn-dlp kernel: PM: Registered nosave memory: [mem 0x000f0000-0x000fffff] Jan 10 07:52:53 hn-dlp kernel: [mem 0x60000000-0xfeffbfff] available for PCI devices Jan 10 07:52:53 hn-dlp kernel: Booting paravirtualized kernel on KVM Jan 10 07:52:53 hn-dlp kernel: clocksource: refined-jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 1910969940391419 ns Jan 10 07:52:53 hn-dlp kernel: setup_percpu: NR_CPUS:8192 nr_cpumask_bits:4 nr_cpu_ids:4 nr_node_ids:1 Jan 10 07:52:53 hn-dlp kernel: percpu: Embedded 54 pages/cpu s184320 r8192 d28672 u524288 Jan 10 07:52:53 hn-dlp kernel: KVM setup async PF for cpu 0 Jan 10 07:52:53 hn-dlp kernel: kvm-stealtime: cpu 0, msr 5fc2c080 Jan 10 07:52:53 hn-dlp kernel: PV qspinlock hash table entries: 256 (order: 0, 4096 bytes) Jan 10 07:52:53 hn-dlp kernel: Built 1 zonelists, mobility grouping on. Total pages: 386778 Jan 10 07:52:53 hn-dlp kernel: Policy zone: DMA32 Jan 10 07:52:53 hn-dlp kernel: Kernel command line: BOOT_IMAGE=(hd0,msdos1)/vmlinuz-4.18.0-240.1.1.el8_3.x86_64 root=UUID=81811398-0853-43ac-b0da-dfc8f2c4dab8 ro crashkernel=auto resume=UUID=40a4da38-bc2d-4c40-afb2-04e76fccea50 rhgb quiet Jan 10 07:52:53 hn-dlp kernel: Specific versions of hardware are certified with Red Hat Enterprise Linux 8. Please see the list of hardware certified with Red Hat Enterprise Linux 8 at https://catalog.redhat.com. Jan 10 07:52:53 hn-dlp kernel: Memory: 261120K/1572320K available (12292K kernel code, 2184K rwdata, 3960K rodata, 2428K init, 15440K bss, 260296K reserved, 0K cma-reserved) Jan 10 07:52:53 hn-dlp kernel: random: get_random_u64 called from cache_random_seq_create+0x7c/0x140 with crng_init=0 Jan 10 07:52:53 hn-dlp kernel: SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=4, Nodes=1 Jan 10 07:52:53 hn-dlp kernel: Kernel/User page tables isolation: enabled Jan 10 07:52:53 hn-dlp kernel: ftrace: allocating 37442 entries in 147 pages Jan 10 07:52:53 hn-dlp kernel: ftrace: allocated 147 pages with 4 groups Jan 10 07:52:53 hn-dlp kernel: rcu: Hierarchical RCU implementation. Jan 10 07:52:53 hn-dlp kernel: rcu: #011RCU restricting CPUs from NR_CPUS=8192 to nr_cpu_ids=4. Jan 10 07:52:53 hn-dlp kernel: rcu: RCU calculated value of scheduler-enlistment delay is 100 jiffies. Jan 10 07:52:53 hn-dlp kernel: rcu: Adjusting geometry for rcu_fanout_leaf=16, nr_cpu_ids=4 Jan 10 07:52:53 hn-dlp kernel: NR_IRQS: 524544, nr_irqs: 456, preallocated irqs: 16 Jan 10 07:52:53 hn-dlp kernel: Console: colour VGA+ 80x25 Jan 10 07:52:53 hn-dlp kernel: printk: console [tty0] enabled Jan 10 07:52:53 hn-dlp kernel: ACPI: Core revision 20200110 Jan 10 07:52:53 hn-dlp kernel: clocksource: hpet: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604467 ns Jan 10 07:52:53 hn-dlp kernel: APIC: Switch to symmetric I/O mode setup Jan 10 07:52:53 hn-dlp kernel: x2apic enabled Jan 10 07:52:53 hn-dlp kernel: Switched APIC routing to physical x2apic. Jan 10 07:52:53 hn-dlp kernel: ..TIMER: vector=0x30 apic1=0 pin1=2 apic2=-1 pin2=-1 Jan 10 07:52:53 hn-dlp kernel: clocksource: tsc-early: mask: 0xffffffffffffffff max_cycles: 0x3102659f42d, max_idle_ns: 440795274465 ns Jan 10 07:52:53 hn-dlp kernel: Calibrating delay loop (skipped) preset value.. 6800.04 BogoMIPS (lpj=3400024) Jan 10 07:52:53 hn-dlp kernel: pid_max: default: 32768 minimum: 301 Jan 10 07:52:53 hn-dlp kernel: Security Framework initialized Jan 10 07:52:53 hn-dlp kernel: Yama: becoming mindful. Jan 10 07:52:53 hn-dlp kernel: SELinux: Initializing. Jan 10 07:52:53 hn-dlp kernel: Dentry cache hash table entries: 262144 (order: 9, 2097152 bytes) Jan 10 07:52:53 hn-dlp kernel: Inode-cache hash table entries: 131072 (order: 8, 1048576 bytes) Jan 10 07:52:53 hn-dlp kernel: Mount-cache hash table entries: 4096 (order: 3, 32768 bytes) Jan 10 07:52:53 hn-dlp kernel: Mountpoint-cache hash table entries: 4096 (order: 3, 32768 bytes) Jan 10 07:52:53 hn-dlp kernel: Last level iTLB entries: 4KB 0, 2MB 0, 4MB 0 Jan 10 07:52:53 hn-dlp kernel: Last level dTLB entries: 4KB 0, 2MB 0, 4MB 0, 1GB 0 Jan 10 07:52:53 hn-dlp kernel: FEATURE SPEC_CTRL Not Present Jan 10 07:52:53 hn-dlp kernel: FEATURE IBPB_SUPPORT Not Present Jan 10 07:52:53 hn-dlp kernel: Spectre V1 : Mitigation: usercopy/swapgs barriers and __user pointer sanitization Jan 10 07:52:53 hn-dlp kernel: Spectre V2 : Mitigation: Full generic retpoline Jan 10 07:52:53 hn-dlp kernel: Spectre V2 : Spectre v2 / SpectreRSB mitigation: Filling RSB on context switch Jan 10 07:52:53 hn-dlp kernel: Speculative Store Bypass: Vulnerable Jan 10 07:52:53 hn-dlp kernel: MDS: Vulnerable: Clear CPU buffers attempted, no microcode Jan 10 07:52:53 hn-dlp kernel: Freeing SMP alternatives memory: 32K Jan 10 07:52:53 hn-dlp kernel: smpboot: CPU0: Intel Common KVM processor (family: 0xf, model: 0x6, stepping: 0x1) Jan 10 07:52:53 hn-dlp kernel: Performance Events: unsupported Netburst CPU model 6 no PMU driver, software events only. Jan 10 07:52:53 hn-dlp kernel: rcu: Hierarchical SRCU implementation. Jan 10 07:52:53 hn-dlp kernel: NMI watchdog: Perf NMI watchdog permanently disabled Jan 10 07:52:53 hn-dlp kernel: smp: Bringing up secondary CPUs ... Jan 10 07:52:53 hn-dlp kernel: x86: Booting SMP configuration: Jan 10 07:52:53 hn-dlp kernel: .... node #0, CPUs: #1 Jan 10 07:52:53 hn-dlp kernel: kvm-clock: cpu 1, msr 13201041, secondary cpu clock Jan 10 07:52:53 hn-dlp kernel: KVM setup async PF for cpu 1 Jan 10 07:52:53 hn-dlp kernel: kvm-stealtime: cpu 1, msr 5fcac080 Jan 10 07:52:53 hn-dlp kernel: #2 Jan 10 07:52:53 hn-dlp kernel: kvm-clock: cpu 2, msr 13201081, secondary cpu clock Jan 10 07:52:53 hn-dlp kernel: KVM setup async PF for cpu 2 Jan 10 07:52:53 hn-dlp kernel: kvm-stealtime: cpu 2, msr 5fd2c080 Jan 10 07:52:53 hn-dlp kernel: #3 Jan 10 07:52:53 hn-dlp kernel: kvm-clock: cpu 3, msr 132010c1, secondary cpu clock Jan 10 07:52:53 hn-dlp kernel: KVM setup async PF for cpu 3 Jan 10 07:52:53 hn-dlp kernel: kvm-stealtime: cpu 3, msr 5fdac080 Jan 10 07:52:53 hn-dlp kernel: smp: Brought up 1 node, 4 CPUs Jan 10 07:52:53 hn-dlp kernel: smpboot: Max logical packages: 1 Jan 10 07:52:53 hn-dlp kernel: smpboot: Total of 4 processors activated (27200.19 BogoMIPS) Jan 10 07:52:53 hn-dlp kernel: node 0 deferred pages initialised in 7ms Jan 10 07:52:53 hn-dlp kernel: devtmpfs: initialized Jan 10 07:52:53 hn-dlp kernel: x86/mm: Memory block size: 128MB Jan 10 07:52:53 hn-dlp kernel: clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 1911260446275000 ns Jan 10 07:52:53 hn-dlp kernel: futex hash table entries: 1024 (order: 4, 65536 bytes) Jan 10 07:52:53 hn-dlp kernel: pinctrl core: initialized pinctrl subsystem Jan 10 07:52:53 hn-dlp kernel: NET: Registered protocol family 16 Jan 10 07:52:53 hn-dlp kernel: audit: initializing netlink subsys (disabled) Jan 10 07:52:53 hn-dlp kernel: audit: type=2000 audit(1610261572.274:1): state=initialized audit_enabled=0 res=1 Jan 10 07:52:53 hn-dlp kernel: cpuidle: using governor menu Jan 10 07:52:53 hn-dlp kernel: ACPI: bus type PCI registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: ACPI Hot Plug PCI Controller Driver version: 0.5 Jan 10 07:52:53 hn-dlp kernel: PCI: Using configuration type 1 for base access Jan 10 07:52:53 hn-dlp kernel: HugeTLB registered 2.00 MiB page size, pre-allocated 0 pages Jan 10 07:52:53 hn-dlp kernel: cryptd: max_cpu_qlen set to 1000 Jan 10 07:52:53 hn-dlp kernel: ACPI: Added _OSI(Module Device) Jan 10 07:52:53 hn-dlp kernel: ACPI: Added _OSI(Processor Device) Jan 10 07:52:53 hn-dlp kernel: ACPI: Added _OSI(3.0 _SCP Extensions) Jan 10 07:52:53 hn-dlp kernel: ACPI: Added _OSI(Processor Aggregator Device) Jan 10 07:52:53 hn-dlp kernel: ACPI: Added _OSI(Linux-Dell-Video) Jan 10 07:52:53 hn-dlp kernel: ACPI: Added _OSI(Linux-Lenovo-NV-HDMI-Audio) Jan 10 07:52:53 hn-dlp kernel: ACPI: Added _OSI(Linux-HPI-Hybrid-Graphics) Jan 10 07:52:53 hn-dlp kernel: ACPI: 2 ACPI AML tables successfully acquired and loaded Jan 10 07:52:53 hn-dlp kernel: ACPI: Interpreter enabled Jan 10 07:52:53 hn-dlp kernel: ACPI: (supports S0 S3 S4 S5) Jan 10 07:52:53 hn-dlp kernel: ACPI: Using IOAPIC for interrupt routing Jan 10 07:52:53 hn-dlp kernel: PCI: Using host bridge windows from ACPI; if necessary, use "pci=nocrs" and report a bug Jan 10 07:52:53 hn-dlp kernel: ACPI: Enabled 3 GPEs in block 00 to 0F Jan 10 07:52:53 hn-dlp kernel: ACPI: PCI Root Bridge [PCI0] (domain 0000 [bus 00-ff]) Jan 10 07:52:53 hn-dlp kernel: acpi PNP0A03:00: _OSC: OS supports [ASPM ClockPM Segments MSI EDR HPX-Type3] Jan 10 07:52:53 hn-dlp kernel: acpi PNP0A03:00: fail to add MMCONFIG information, can't access extended PCI configuration space under this bridge. Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [4] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [5] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [6] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [7] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [8] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [9] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [10] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [11] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [12] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [13] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [14] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [15] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [16] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [17] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [18] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [19] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [20] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [21] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [22] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [23] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [24] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [25] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [26] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [27] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [28] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [29] registered Jan 10 07:52:53 hn-dlp kernel: PCI host bridge to bus 0000:00 Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:00: root bus resource [io 0x0000-0x0cf7 window] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:00: root bus resource [io 0x0d00-0xffff window] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:00: root bus resource [mem 0x000a0000-0x000bffff window] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:00: root bus resource [mem 0x60000000-0xfebfffff window] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:00: root bus resource [mem 0x100000000-0x17fffffff window] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:00: root bus resource [bus 00-ff] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:00.0: [8086:1237] type 00 class 0x060000 Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:01.0: [8086:7000] type 00 class 0x060100 Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:01.1: [8086:7010] type 00 class 0x010180 Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:01.1: reg 0x20: [io 0xe140-0xe14f] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:01.1: legacy IDE quirk: reg 0x10: [io 0x01f0-0x01f7] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:01.1: legacy IDE quirk: reg 0x14: [io 0x03f6] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:01.1: legacy IDE quirk: reg 0x18: [io 0x0170-0x0177] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:01.1: legacy IDE quirk: reg 0x1c: [io 0x0376] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:01.2: [8086:7020] type 00 class 0x0c0300 Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:01.2: reg 0x20: [io 0xe100-0xe11f] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:01.3: [8086:7113] type 00 class 0x068000 Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:01.3: quirk: [io 0x0600-0x063f] claimed by PIIX4 ACPI Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:01.3: quirk: [io 0x0700-0x070f] claimed by PIIX4 SMB Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:02.0: [1234:1111] type 00 class 0x030000 Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:02.0: reg 0x10: [mem 0xfd000000-0xfdffffff pref] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:02.0: reg 0x18: [mem 0xfea50000-0xfea50fff] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:02.0: reg 0x30: [mem 0xfea40000-0xfea4ffff pref] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:03.0: [1af4:1002] type 00 class 0x00ff00 Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:03.0: reg 0x10: [io 0xe080-0xe0bf] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:03.0: reg 0x20: [mem 0xfe400000-0xfe403fff 64bit pref] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:08.0: [1af4:1003] type 00 class 0x078000 Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:08.0: reg 0x10: [io 0xe0c0-0xe0ff] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:08.0: reg 0x14: [mem 0xfea51000-0xfea51fff] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:08.0: reg 0x20: [mem 0xfe404000-0xfe407fff 64bit pref] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:0a.0: [1af4:1001] type 00 class 0x010000 Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:0a.0: reg 0x10: [io 0xe000-0xe07f] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:0a.0: reg 0x14: [mem 0xfea52000-0xfea52fff] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:0a.0: reg 0x20: [mem 0xfe408000-0xfe40bfff 64bit pref] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:12.0: [1af4:1000] type 00 class 0x020000 Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:12.0: reg 0x10: [io 0xe120-0xe13f] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:12.0: reg 0x14: [mem 0xfea53000-0xfea53fff] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:12.0: reg 0x20: [mem 0xfe40c000-0xfe40ffff 64bit pref] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:12.0: reg 0x30: [mem 0xfea00000-0xfea3ffff pref] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1e.0: [1b36:0001] type 01 class 0x060400 Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1e.0: reg 0x10: [mem 0xfea54000-0xfea540ff 64bit] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1f.0: [1b36:0001] type 01 class 0x060400 Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1f.0: reg 0x10: [mem 0xfea55000-0xfea550ff 64bit] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:01: extended config space not accessible Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [0] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [1] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [3-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [4-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [5-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [6-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [7-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [8-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [9-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [10-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [11-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [12-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [13-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [14-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [15-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [16-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [17-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [18-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [19-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [20-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [21-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [22-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [23-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [24-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [25-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [26-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [27-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [28-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [29-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [30] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [31] registered Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1e.0: PCI bridge to [bus 01] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1e.0: bridge window [io 0xd000-0xdfff] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1e.0: bridge window [mem 0xfe800000-0xfe9fffff] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1e.0: bridge window [mem 0xfe200000-0xfe3fffff 64bit pref] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:02: extended config space not accessible Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [0-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [1-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [2-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [3-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [4-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [5-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [6-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [7-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [8-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [9-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [10-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [11-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [12-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [13-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [14-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [15-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [16-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [17-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [18-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [19-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [20-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [21-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [22-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [23-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [24-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [25-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [26-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [27-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [28-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [29-3] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [30-2] registered Jan 10 07:52:53 hn-dlp kernel: acpiphp: Slot [31-2] registered Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1f.0: PCI bridge to [bus 02] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1f.0: bridge window [io 0xc000-0xcfff] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1f.0: bridge window [mem 0xfe600000-0xfe7fffff] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1f.0: bridge window [mem 0xfe000000-0xfe1fffff 64bit pref] Jan 10 07:52:53 hn-dlp kernel: ACPI: PCI Interrupt Link [LNKA] (IRQs 5 *10 11) Jan 10 07:52:53 hn-dlp kernel: ACPI: PCI Interrupt Link [LNKB] (IRQs 5 *10 11) Jan 10 07:52:53 hn-dlp kernel: ACPI: PCI Interrupt Link [LNKC] (IRQs 5 10 *11) Jan 10 07:52:53 hn-dlp kernel: ACPI: PCI Interrupt Link [LNKD] (IRQs 5 10 *11) Jan 10 07:52:53 hn-dlp kernel: ACPI: PCI Interrupt Link [LNKS] (IRQs *9) Jan 10 07:52:53 hn-dlp kernel: iommu: Default domain type: Passthrough Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:02.0: vgaarb: setting as boot VGA device Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:02.0: vgaarb: VGA device added: decodes=io+mem,owns=io+mem,locks=none Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:02.0: vgaarb: bridge control possible Jan 10 07:52:53 hn-dlp kernel: vgaarb: loaded Jan 10 07:52:53 hn-dlp kernel: SCSI subsystem initialized Jan 10 07:52:53 hn-dlp kernel: ACPI: bus type USB registered Jan 10 07:52:53 hn-dlp kernel: usbcore: registered new interface driver usbfs Jan 10 07:52:53 hn-dlp kernel: usbcore: registered new interface driver hub Jan 10 07:52:53 hn-dlp kernel: usbcore: registered new device driver usb Jan 10 07:52:53 hn-dlp kernel: pps_core: LinuxPPS API ver. 1 registered Jan 10 07:52:53 hn-dlp kernel: pps_core: Software ver. 5.3.6 - Copyright 2005-2007 Rodolfo Giometti <giometti@linux.it> Jan 10 07:52:53 hn-dlp kernel: PTP clock support registered Jan 10 07:52:53 hn-dlp kernel: EDAC MC: Ver: 3.0.0 Jan 10 07:52:53 hn-dlp kernel: PCI: Using ACPI for IRQ routing Jan 10 07:52:53 hn-dlp kernel: NetLabel: Initializing Jan 10 07:52:53 hn-dlp kernel: NetLabel: domain hash size = 128 Jan 10 07:52:53 hn-dlp kernel: NetLabel: protocols = UNLABELED CIPSOv4 CALIPSO Jan 10 07:52:53 hn-dlp kernel: NetLabel: unlabeled traffic allowed by default Jan 10 07:52:53 hn-dlp kernel: HPET: 3 timers in total, 0 timers will be used for per-cpu timer Jan 10 07:52:53 hn-dlp kernel: hpet0: at MMIO 0xfed00000, IRQs 2, 8, 0 Jan 10 07:52:53 hn-dlp kernel: hpet0: 3 comparators, 64-bit 100.000000 MHz counter Jan 10 07:52:53 hn-dlp kernel: clocksource: Switched to clocksource kvm-clock Jan 10 07:52:53 hn-dlp kernel: VFS: Disk quotas dquot_6.6.0 Jan 10 07:52:53 hn-dlp kernel: VFS: Dquot-cache hash table entries: 512 (order 0, 4096 bytes) Jan 10 07:52:53 hn-dlp kernel: pnp: PnP ACPI init Jan 10 07:52:53 hn-dlp kernel: pnp: PnP ACPI: found 4 devices Jan 10 07:52:53 hn-dlp kernel: clocksource: acpi_pm: mask: 0xffffff max_cycles: 0xffffff, max_idle_ns: 2085701024 ns Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1e.0: PCI bridge to [bus 01] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1e.0: bridge window [io 0xd000-0xdfff] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1e.0: bridge window [mem 0xfe800000-0xfe9fffff] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1e.0: bridge window [mem 0xfe200000-0xfe3fffff 64bit pref] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1f.0: PCI bridge to [bus 02] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1f.0: bridge window [io 0xc000-0xcfff] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1f.0: bridge window [mem 0xfe600000-0xfe7fffff] Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:1f.0: bridge window [mem 0xfe000000-0xfe1fffff 64bit pref] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:00: resource 4 [io 0x0000-0x0cf7 window] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:00: resource 5 [io 0x0d00-0xffff window] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:00: resource 6 [mem 0x000a0000-0x000bffff window] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:00: resource 7 [mem 0x60000000-0xfebfffff window] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:00: resource 8 [mem 0x100000000-0x17fffffff window] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:01: resource 0 [io 0xd000-0xdfff] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:01: resource 1 [mem 0xfe800000-0xfe9fffff] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:01: resource 2 [mem 0xfe200000-0xfe3fffff 64bit pref] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:02: resource 0 [io 0xc000-0xcfff] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:02: resource 1 [mem 0xfe600000-0xfe7fffff] Jan 10 07:52:53 hn-dlp kernel: pci_bus 0000:02: resource 2 [mem 0xfe000000-0xfe1fffff 64bit pref] Jan 10 07:52:53 hn-dlp kernel: NET: Registered protocol family 2 Jan 10 07:52:53 hn-dlp kernel: tcp_listen_portaddr_hash hash table entries: 1024 (order: 2, 16384 bytes) Jan 10 07:52:53 hn-dlp kernel: TCP established hash table entries: 16384 (order: 5, 131072 bytes) Jan 10 07:52:53 hn-dlp kernel: TCP bind hash table entries: 16384 (order: 6, 262144 bytes) Jan 10 07:52:53 hn-dlp kernel: TCP: Hash tables configured (established 16384 bind 16384) Jan 10 07:52:53 hn-dlp kernel: UDP hash table entries: 1024 (order: 3, 32768 bytes) Jan 10 07:52:53 hn-dlp kernel: UDP-Lite hash table entries: 1024 (order: 3, 32768 bytes) Jan 10 07:52:53 hn-dlp kernel: NET: Registered protocol family 1 Jan 10 07:52:53 hn-dlp kernel: NET: Registered protocol family 44 Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:00.0: Limiting direct PCI/PCI transfers Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:01.0: PIIX3: Enabling Passive Release Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:01.0: Activating ISA DMA hang workarounds Jan 10 07:52:53 hn-dlp kernel: PCI Interrupt Link [LNKD] enabled at IRQ 11 Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:01.2: quirk_usb_early_handoff+0x0/0x6a9 took 33813 usecs Jan 10 07:52:53 hn-dlp kernel: pci 0000:00:02.0: Video device with shadowed ROM at [mem 0x000c0000-0x000dffff] Jan 10 07:52:53 hn-dlp kernel: PCI: CLS 0 bytes, default 64 Jan 10 07:52:53 hn-dlp kernel: Unpacking initramfs... Jan 10 07:52:53 hn-dlp kernel: Freeing initrd memory: 25036K Jan 10 07:52:53 hn-dlp kernel: clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x3102659f42d, max_idle_ns: 440795274465 ns Jan 10 07:52:53 hn-dlp kernel: Initialise system trusted keyrings Jan 10 07:52:53 hn-dlp kernel: Key type blacklist registered Jan 10 07:52:53 hn-dlp kernel: workingset: timestamp_bits=36 max_order=19 bucket_order=0 Jan 10 07:52:53 hn-dlp kernel: zbud: loaded Jan 10 07:52:53 hn-dlp kernel: pstore: using deflate compression Jan 10 07:52:53 hn-dlp kernel: Platform Keyring initialized Jan 10 07:52:53 hn-dlp kernel: NET: Registered protocol family 38 Jan 10 07:52:53 hn-dlp kernel: Key type asymmetric registered Jan 10 07:52:53 hn-dlp kernel: Asymmetric key parser 'x509' registered Jan 10 07:52:53 hn-dlp kernel: Block layer SCSI generic (bsg) driver version 0.4 loaded (major 247) Jan 10 07:52:53 hn-dlp kernel: io scheduler mq-deadline registered Jan 10 07:52:53 hn-dlp kernel: io scheduler kyber registered Jan 10 07:52:53 hn-dlp kernel: io scheduler bfq registered Jan 10 07:52:53 hn-dlp kernel: atomic64_test: passed for x86-64 platform with CX8 and with SSE Jan 10 07:52:53 hn-dlp kernel: shpchp 0000:00:1e.0: Requesting control of SHPC hotplug via OSHP (\_SB_.PCI0.SF0_) Jan 10 07:52:53 hn-dlp kernel: shpchp 0000:00:1e.0: Requesting control of SHPC hotplug via OSHP (\_SB_.PCI0) Jan 10 07:52:53 hn-dlp kernel: shpchp 0000:00:1e.0: Cannot get control of SHPC hotplug Jan 10 07:52:53 hn-dlp kernel: shpchp 0000:00:1f.0: Requesting control of SHPC hotplug via OSHP (\_SB_.PCI0.SF8_) Jan 10 07:52:53 hn-dlp kernel: shpchp 0000:00:1f.0: Requesting control of SHPC hotplug via OSHP (\_SB_.PCI0) Jan 10 07:52:53 hn-dlp kernel: shpchp 0000:00:1f.0: Cannot get control of SHPC hotplug Jan 10 07:52:53 hn-dlp kernel: shpchp: Standard Hot Plug PCI Controller Driver version: 0.4 Jan 10 07:52:53 hn-dlp kernel: input: Power Button as /devices/LNXSYSTM:00/LNXPWRBN:00/input/input0 Jan 10 07:52:53 hn-dlp kernel: ACPI: Power Button [PWRF] Jan 10 07:52:53 hn-dlp kernel: PCI Interrupt Link [LNKC] enabled at IRQ 10 Jan 10 07:52:53 hn-dlp kernel: PCI Interrupt Link [LNKB] enabled at IRQ 10 Jan 10 07:52:53 hn-dlp kernel: Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled Jan 10 07:52:53 hn-dlp kernel: Non-volatile memory driver v1.3 Jan 10 07:52:53 hn-dlp kernel: rdac: device handler registered Jan 10 07:52:53 hn-dlp kernel: hp_sw: device handler registered Jan 10 07:52:53 hn-dlp kernel: emc: device handler registered Jan 10 07:52:53 hn-dlp kernel: alua: device handler registered Jan 10 07:52:53 hn-dlp kernel: libphy: Fixed MDIO Bus: probed Jan 10 07:52:53 hn-dlp kernel: ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver Jan 10 07:52:53 hn-dlp kernel: ehci-pci: EHCI PCI platform driver Jan 10 07:52:53 hn-dlp kernel: ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver Jan 10 07:52:53 hn-dlp kernel: ohci-pci: OHCI PCI platform driver Jan 10 07:52:53 hn-dlp kernel: uhci_hcd: USB Universal Host Controller Interface driver Jan 10 07:52:53 hn-dlp kernel: uhci_hcd 0000:00:01.2: UHCI Host Controller Jan 10 07:52:53 hn-dlp kernel: uhci_hcd 0000:00:01.2: new USB bus registered, assigned bus number 1 Jan 10 07:52:53 hn-dlp kernel: uhci_hcd 0000:00:01.2: detected 2 ports Jan 10 07:52:53 hn-dlp kernel: uhci_hcd 0000:00:01.2: irq 11, io base 0x0000e100 Jan 10 07:52:53 hn-dlp kernel: usb usb1: New USB device found, idVendor=1d6b, idProduct=0001, bcdDevice= 4.18 Jan 10 07:52:53 hn-dlp kernel: usb usb1: New USB device strings: Mfr=3, Product=2, SerialNumber=1 Jan 10 07:52:53 hn-dlp kernel: usb usb1: Product: UHCI Host Controller Jan 10 07:52:53 hn-dlp kernel: usb usb1: Manufacturer: Linux 4.18.0-240.1.1.el8_3.x86_64 uhci_hcd Jan 10 07:52:53 hn-dlp kernel: usb usb1: SerialNumber: 0000:00:01.2 Jan 10 07:52:53 hn-dlp kernel: hub 1-0:1.0: USB hub found Jan 10 07:52:53 hn-dlp kernel: hub 1-0:1.0: 2 ports detected Jan 10 07:52:53 hn-dlp kernel: usbcore: registered new interface driver usbserial_generic Jan 10 07:52:53 hn-dlp kernel: usbserial: USB Serial support registered for generic Jan 10 07:52:53 hn-dlp kernel: i8042: PNP: PS/2 Controller [PNP0303:KBD,PNP0f13:MOU] at 0x60,0x64 irq 1,12 Jan 10 07:52:53 hn-dlp kernel: serio: i8042 KBD port at 0x60,0x64 irq 1 Jan 10 07:52:53 hn-dlp kernel: serio: i8042 AUX port at 0x60,0x64 irq 12 Jan 10 07:52:53 hn-dlp kernel: mousedev: PS/2 mouse device common for all mice Jan 10 07:52:53 hn-dlp kernel: rtc_cmos 00:03: RTC can wake from S4 Jan 10 07:52:53 hn-dlp kernel: input: AT Translated Set 2 keyboard as /devices/platform/i8042/serio0/input/input1 Jan 10 07:52:53 hn-dlp kernel: rtc_cmos 00:03: registered as rtc0 Jan 10 07:52:53 hn-dlp kernel: rtc_cmos 00:03: alarms up to one day, y3k, 242 bytes nvram, hpet irqs Jan 10 07:52:53 hn-dlp kernel: intel_pstate: CPU model not supported Jan 10 07:52:53 hn-dlp kernel: input: VirtualPS/2 VMware VMMouse as /devices/platform/i8042/serio1/input/input4 Jan 10 07:52:53 hn-dlp kernel: hidraw: raw HID events driver (C) Jiri Kosina Jan 10 07:52:53 hn-dlp kernel: usbcore: registered new interface driver usbhid Jan 10 07:52:53 hn-dlp kernel: usbhid: USB HID core driver Jan 10 07:52:53 hn-dlp kernel: drop_monitor: Initializing network drop monitor service Jan 10 07:52:53 hn-dlp kernel: Initializing XFRM netlink socket Jan 10 07:52:53 hn-dlp kernel: input: VirtualPS/2 VMware VMMouse as /devices/platform/i8042/serio1/input/input3 Jan 10 07:52:53 hn-dlp kernel: NET: Registered protocol family 10 Jan 10 07:52:53 hn-dlp kernel: Segment Routing with IPv6 Jan 10 07:52:53 hn-dlp kernel: NET: Registered protocol family 17 Jan 10 07:52:53 hn-dlp kernel: mpls_gso: MPLS GSO support Jan 10 07:52:53 hn-dlp kernel: core: Using 10 MCE banks Jan 10 07:52:53 hn-dlp kernel: sched_clock: Marking stable (699905100, 0)->(966516835, -266611735) Jan 10 07:52:53 hn-dlp kernel: registered taskstats version 1 Jan 10 07:52:53 hn-dlp kernel: Loading compiled-in X.509 certificates Jan 10 07:52:53 hn-dlp kernel: Loaded X.509 cert 'CentOS kernel signing key: 8722700eaf478598cea8937c54c436d1addc428d' Jan 10 07:52:53 hn-dlp kernel: Loaded X.509 cert 'CentOS Linux Driver update signing key: 29bd4c0d06d2e9911044b5dc973309139b51d6d5' Jan 10 07:52:53 hn-dlp kernel: Loaded X.509 cert 'CentOS Linux kpatch signing key: b49f086205909dc4da2cfa99376fb191d2f09e78' Jan 10 07:52:53 hn-dlp kernel: zswap: loaded using pool lzo/zbud Jan 10 07:52:53 hn-dlp kernel: page_owner is disabled Jan 10 07:52:53 hn-dlp kernel: Key type big_key registered Jan 10 07:52:53 hn-dlp kernel: Key type encrypted registered Jan 10 07:52:53 hn-dlp kernel: ima: No TPM chip found, activating TPM-bypass! Jan 10 07:52:53 hn-dlp kernel: ima: Allocated hash algorithm: sha1 Jan 10 07:52:53 hn-dlp kernel: ima: No architecture policies found Jan 10 07:52:53 hn-dlp kernel: evm: Initialising EVM extended attributes: Jan 10 07:52:53 hn-dlp kernel: evm: security.selinux Jan 10 07:52:53 hn-dlp kernel: evm: security.ima Jan 10 07:52:53 hn-dlp kernel: evm: security.capability Jan 10 07:52:53 hn-dlp kernel: evm: HMAC attrs: 0x1 Jan 10 07:52:53 hn-dlp kernel: rtc_cmos 00:03: setting system clock to 2021-01-10 06:52:52 UTC (1610261572) Jan 10 07:52:53 hn-dlp kernel: Freeing unused decrypted memory: 2040K Jan 10 07:52:53 hn-dlp kernel: Freeing unused kernel memory: 2428K Jan 10 07:52:53 hn-dlp kernel: Write protecting the kernel read-only data: 18432k Jan 10 07:52:53 hn-dlp kernel: Freeing unused kernel memory: 2016K Jan 10 07:52:53 hn-dlp kernel: Freeing unused kernel memory: 136K Jan 10 07:52:53 hn-dlp systemd[1]: systemd 239 (239-41.el8_3.1) running in system mode. (+PAM +AUDIT +SELINUX +IMA -APPARMOR +SMACK +SYSVINIT +UTMP +LIBCRYPTSETUP +GCRYPT +GNUTLS +ACL +XZ +LZ4 +SECCOMP +BLKID +ELFUTILS +KMOD +IDN2 -IDN +PCRE2 default-hierarchy=legacy) Jan 10 07:52:53 hn-dlp systemd[1]: Detected virtualization kvm. Jan 10 07:52:53 hn-dlp systemd[1]: Detected architecture x86-64. Jan 10 07:52:53 hn-dlp systemd[1]: Running in initial RAM disk. Jan 10 07:52:53 hn-dlp systemd[1]: Set hostname to <hn-dlp.ipa.example.local>. Jan 10 07:52:53 hn-dlp kernel: random: systemd: uninitialized urandom read (16 bytes read) Jan 10 07:52:53 hn-dlp systemd[1]: Listening on udev Kernel Socket. Jan 10 07:52:53 hn-dlp kernel: random: systemd: uninitialized urandom read (16 bytes read) Jan 10 07:52:53 hn-dlp systemd[1]: Reached target Timers. Jan 10 07:52:53 hn-dlp kernel: random: systemd: uninitialized urandom read (16 bytes read) Jan 10 07:52:53 hn-dlp systemd[1]: Listening on Journal Socket (/dev/log). Jan 10 07:52:53 hn-dlp systemd[1]: Listening on udev Control Socket. Jan 10 07:52:53 hn-dlp systemd[1]: Listening on Journal Socket. Jan 10 07:52:53 hn-dlp kernel: usb 1-1: new full-speed USB device number 2 using uhci_hcd Jan 10 07:52:53 hn-dlp kernel: usb 1-1: New USB device found, idVendor=0627, idProduct=0001, bcdDevice= 0.00 Jan 10 07:52:53 hn-dlp kernel: usb 1-1: New USB device strings: Mfr=1, Product=3, SerialNumber=10 Jan 10 07:52:53 hn-dlp kernel: usb 1-1: Product: QEMU USB Tablet Jan 10 07:52:53 hn-dlp kernel: usb 1-1: Manufacturer: QEMU Jan 10 07:52:53 hn-dlp kernel: usb 1-1: SerialNumber: 28754-0000:00:01.2-1 Jan 10 07:52:53 hn-dlp kernel: input: QEMU QEMU USB Tablet as /devices/pci0000:00/0000:00:01.2/usb1/1-1/1-1:1.0/0003:0627:0001.0001/input/input5 Jan 10 07:52:53 hn-dlp kernel: hid-generic 0003:0627:0001.0001: input,hidraw0: USB HID v0.01 Mouse [QEMU QEMU USB Tablet] on usb-0000:00:01.2-1/input0 Jan 10 07:52:53 hn-dlp systemd-journald[208]: Journal started Jan 10 07:52:53 hn-dlp systemd-journald[208]: Runtime journal (/run/log/journal/fed2b1b6cbc74355bce5e4c5b7e8359e) is 8.0M, max 65.6M, 57.6M free. Jan 10 07:52:53 hn-dlp rngd[205]: Initializing available sources Jan 10 07:52:53 hn-dlp rngd[205]: Failed to init entropy source hwrng Jan 10 07:52:53 hn-dlp rngd[205]: Failed to init entropy source rdrand Jan 10 07:52:53 hn-dlp dracut-cmdline[239]: dracut-8 dracut-049-95.git20200804.el8 Jan 10 07:52:53 hn-dlp dracut-cmdline[239]: Using kernel command line parameters: BOOT_IMAGE=(hd0,msdos1)/vmlinuz-4.18.0-240.1.1.el8_3.x86_64 root=UUID=81811398-0853-43ac-b0da-dfc8f2c4dab8 ro crashkernel=auto resume=UUID=40a4da38-bc2d-4c40-afb2-04e76fccea50 rhgb quiet Jan 10 07:52:53 hn-dlp systemd[1]: Started dracut cmdline hook. Jan 10 07:52:53 hn-dlp systemd[1]: Starting dracut pre-udev hook... Jan 10 07:52:54 hn-dlp systemd[1]: Started dracut pre-udev hook. Jan 10 07:52:54 hn-dlp systemd[1]: Starting udev Kernel Device Manager... Jan 10 07:52:54 hn-dlp systemd[1]: Started udev Kernel Device Manager. Jan 10 07:52:54 hn-dlp systemd[1]: Starting udev Coldplug all Devices... Jan 10 07:52:54 hn-dlp systemd[1]: Mounting Kernel Configuration File System... Jan 10 07:52:54 hn-dlp systemd[1]: Mounted Kernel Configuration File System. Jan 10 07:52:54 hn-dlp systemd[1]: Started udev Coldplug all Devices. Jan 10 07:52:54 hn-dlp systemd[1]: Starting dracut initqueue hook... Jan 10 07:52:54 hn-dlp systemd[1]: Starting Show Plymouth Boot Screen... Jan 10 07:52:54 hn-dlp systemd[1]: Received SIGRTMIN+20 from PID 362 (plymouthd). Jan 10 07:52:54 hn-dlp kernel: virtio_blk virtio2: [vda] 67108864 512-byte logical blocks (34.4 GB/32.0 GiB) Jan 10 07:52:54 hn-dlp systemd[1]: Started Show Plymouth Boot Screen. Jan 10 07:52:54 hn-dlp systemd[1]: Reached target Paths. Jan 10 07:52:54 hn-dlp systemd[1]: Started Forward Password Requests to Plymouth Directory Watch. Jan 10 07:52:54 hn-dlp systemd-udevd[357]: link_config: autonegotiation is unset or enabled, the speed and duplex are not writable. Jan 10 07:52:55 hn-dlp kernel: vda: vda1 vda2 vda3 vda4 < vda5 vda6 > Jan 10 07:52:55 hn-dlp kernel: scsi host0: ata_piix Jan 10 07:52:55 hn-dlp kernel: scsi host1: ata_piix Jan 10 07:52:55 hn-dlp kernel: ata1: PATA max MWDMA2 cmd 0x1f0 ctl 0x3f6 bmdma 0xe140 irq 14 Jan 10 07:52:55 hn-dlp kernel: ata2: PATA max MWDMA2 cmd 0x170 ctl 0x376 bmdma 0xe148 irq 15 Jan 10 07:52:55 hn-dlp systemd-udevd[357]: link_config: autonegotiation is unset or enabled, the speed and duplex are not writable. Jan 10 07:52:55 hn-dlp kernel: virtio_net virtio3 ens18: renamed from eth0 Jan 10 07:52:55 hn-dlp rngd[205]: Initializing AES buffer Jan 10 07:52:55 hn-dlp rngd[205]: Enabling JITTER rng support Jan 10 07:52:55 hn-dlp rngd[205]: Initializing entropy source jitter Jan 10 07:52:55 hn-dlp kernel: random: crng init done Jan 10 07:52:55 hn-dlp kernel: random: 7 urandom warning(s) missed due to ratelimiting Jan 10 07:52:55 hn-dlp kernel: ata2.00: ATAPI: QEMU DVD-ROM, 2.5+, max UDMA/100 Jan 10 07:52:55 hn-dlp kernel: scsi 1:0:0:0: CD-ROM QEMU QEMU DVD-ROM 2.5+ PQ: 0 ANSI: 5 Jan 10 07:52:55 hn-dlp kernel: scsi 1:0:0:0: Attached scsi generic sg0 type 5 Jan 10 07:52:55 hn-dlp kernel: sr 1:0:0:0: [sr0] scsi3-mmc drive: 4x/4x cd/rw xa/form2 tray Jan 10 07:52:55 hn-dlp kernel: cdrom: Uniform CD-ROM driver Revision: 3.20 Jan 10 07:52:55 hn-dlp systemd[1]: Found device /dev/disk/by-uuid/40a4da38-bc2d-4c40-afb2-04e76fccea50. Jan 10 07:52:55 hn-dlp systemd[1]: Found device /dev/disk/by-uuid/81811398-0853-43ac-b0da-dfc8f2c4dab8. Jan 10 07:52:55 hn-dlp systemd[1]: Reached target Initrd Root Device. Jan 10 07:52:55 hn-dlp systemd[1]: Starting Resume from hibernation using device /dev/disk/by-uuid/40a4da38-bc2d-4c40-afb2-04e76fccea50... Jan 10 07:52:55 hn-dlp systemd-hibernate-resume[389]: Could not resume from '/dev/disk/by-uuid/40a4da38-bc2d-4c40-afb2-04e76fccea50' (253:5). Jan 10 07:52:55 hn-dlp systemd[1]: systemd-hibernate-resume@dev-disk-by\x2duuid-40a4da38\x2dbc2d\x2d4c40\x2dafb2\x2d04e76fccea50.service: Succeeded. Jan 10 07:52:55 hn-dlp systemd[1]: Started Resume from hibernation using device /dev/disk/by-uuid/40a4da38-bc2d-4c40-afb2-04e76fccea50. Jan 10 07:52:55 hn-dlp systemd[1]: Reached target Local File Systems (Pre). Jan 10 07:52:55 hn-dlp systemd[1]: Reached target Local File Systems. Jan 10 07:52:55 hn-dlp systemd[1]: Starting Create Volatile Files and Directories... Jan 10 07:52:55 hn-dlp systemd[1]: Started dracut initqueue hook. Jan 10 07:52:55 hn-dlp systemd[1]: Reached target Remote File Systems (Pre). Jan 10 07:52:55 hn-dlp systemd[1]: Reached target Remote File Systems. Jan 10 07:52:55 hn-dlp systemd[1]: Starting File System Check on /dev/disk/by-uuid/81811398-0853-43ac-b0da-dfc8f2c4dab8... Jan 10 07:52:55 hn-dlp systemd[1]: Started Create Volatile Files and Directories. Jan 10 07:52:55 hn-dlp systemd[1]: Reached target System Initialization. Jan 10 07:52:55 hn-dlp systemd[1]: Reached target Basic System. Jan 10 07:52:55 hn-dlp systemd-fsck[397]: /usr/sbin/fsck.xfs: XFS file system. Jan 10 07:52:55 hn-dlp systemd[1]: Started File System Check on /dev/disk/by-uuid/81811398-0853-43ac-b0da-dfc8f2c4dab8. Jan 10 07:52:55 hn-dlp systemd[1]: Mounting /sysroot... Jan 10 07:52:56 hn-dlp kernel: SGI XFS with ACLs, security attributes, no debug enabled Jan 10 07:52:56 hn-dlp kernel: XFS (vda2): Mounting V5 Filesystem Jan 10 07:52:56 hn-dlp kernel: XFS (vda2): Ending clean mount Jan 10 07:52:56 hn-dlp systemd[1]: Mounted /sysroot. Jan 10 07:52:56 hn-dlp systemd[1]: Reached target Initrd Root File System. Jan 10 07:52:56 hn-dlp systemd[1]: Starting Reload Configuration from the Real Root... Jan 10 07:52:56 hn-dlp systemd[1]: Reloading. Jan 10 07:52:56 hn-dlp systemd[1]: initrd-parse-etc.service: Succeeded. Jan 10 07:52:56 hn-dlp systemd[1]: Started Reload Configuration from the Real Root. Jan 10 07:52:56 hn-dlp systemd[1]: Reached target Initrd File Systems. Jan 10 07:52:56 hn-dlp systemd[1]: Reached target Initrd Default Target. Jan 10 07:52:56 hn-dlp systemd[1]: Starting dracut pre-pivot and cleanup hook... Jan 10 07:52:57 hn-dlp systemd[1]: Started dracut pre-pivot and cleanup hook. Jan 10 07:52:57 hn-dlp systemd[1]: Starting Cleaning Up and Shutting Down Daemons... Jan 10 07:52:57 hn-dlp systemd[1]: Stopped target Timers. Jan 10 07:52:57 hn-dlp systemd[1]: dracut-pre-pivot.service: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped dracut pre-pivot and cleanup hook. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped target Initrd Default Target. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped target Basic System. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped target System Initialization. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped target Swap. Jan 10 07:52:57 hn-dlp systemd[1]: Starting Setup Virtual Console... Jan 10 07:52:57 hn-dlp systemd[1]: Stopping udev Kernel Device Manager... Jan 10 07:52:57 hn-dlp systemd[1]: Stopped target Paths. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped target Slices. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped target Remote File Systems. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped target Remote File Systems (Pre). Jan 10 07:52:57 hn-dlp systemd[1]: dracut-initqueue.service: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped dracut initqueue hook. Jan 10 07:52:57 hn-dlp systemd[1]: systemd-udev-trigger.service: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped udev Coldplug all Devices. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped target Sockets. Jan 10 07:52:57 hn-dlp systemd[1]: Starting Plymouth switch root service... Jan 10 07:52:57 hn-dlp systemd[1]: systemd-sysctl.service: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped Apply Kernel Variables. Jan 10 07:52:57 hn-dlp systemd[1]: systemd-tmpfiles-setup.service: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped Create Volatile Files and Directories. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped target Local File Systems. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped target Local File Systems (Pre). Jan 10 07:52:57 hn-dlp systemd[1]: Stopped target Initrd Root Device. Jan 10 07:52:57 hn-dlp systemd[1]: systemd-udevd.service: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped udev Kernel Device Manager. Jan 10 07:52:57 hn-dlp systemd[1]: initrd-cleanup.service: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Started Cleaning Up and Shutting Down Daemons. Jan 10 07:52:57 hn-dlp systemd[1]: Stopping Hardware RNG Entropy Gatherer Daemon... Jan 10 07:52:57 hn-dlp systemd[1]: systemd-tmpfiles-setup-dev.service: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped Create Static Device Nodes in /dev. Jan 10 07:52:57 hn-dlp systemd[1]: kmod-static-nodes.service: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped Create list of required static device nodes for the current kernel. Jan 10 07:52:57 hn-dlp systemd[1]: dracut-pre-udev.service: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped dracut pre-udev hook. Jan 10 07:52:57 hn-dlp systemd[1]: dracut-cmdline.service: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped dracut cmdline hook. Jan 10 07:52:57 hn-dlp systemd[1]: systemd-udevd-kernel.socket: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Closed udev Kernel Socket. Jan 10 07:52:57 hn-dlp systemd[1]: systemd-udevd-control.socket: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Closed udev Control Socket. Jan 10 07:52:57 hn-dlp systemd[1]: Starting Cleanup udevd DB... Jan 10 07:52:57 hn-dlp systemd[1]: rngd.service: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Stopped Hardware RNG Entropy Gatherer Daemon. Jan 10 07:52:57 hn-dlp systemd[1]: initrd-udevadm-cleanup-db.service: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Started Cleanup udevd DB. Jan 10 07:52:57 hn-dlp systemd[1]: systemd-vconsole-setup.service: Succeeded. Jan 10 07:52:57 hn-dlp systemd[1]: Started Setup Virtual Console. Jan 10 07:52:57 hn-dlp systemd[1]: Reached target Switch Root. Jan 10 07:52:58 hn-dlp systemd[1]: Started Plymouth switch root service. Jan 10 07:52:58 hn-dlp systemd[1]: Starting Switch Root... Jan 10 07:52:58 hn-dlp systemd[1]: Switching root. Jan 10 07:52:58 hn-dlp systemd-journald[208]: Journal stopped Jan 10 07:53:06 hn-dlp systemd-journald[208]: Received SIGTERM from PID 1 (systemd). Jan 10 07:53:06 hn-dlp kernel: printk: systemd: 19 output lines suppressed due to ratelimiting Jan 10 07:53:06 hn-dlp kernel: SELinux: policy capability network_peer_controls=1 Jan 10 07:53:06 hn-dlp kernel: SELinux: policy capability open_perms=1 Jan 10 07:53:06 hn-dlp kernel: SELinux: policy capability extended_socket_class=1 Jan 10 07:53:06 hn-dlp kernel: SELinux: policy capability always_check_network=0 Jan 10 07:53:06 hn-dlp kernel: SELinux: policy capability cgroup_seclabel=1 Jan 10 07:53:06 hn-dlp kernel: SELinux: policy capability nnp_nosuid_transition=1 Jan 10 07:53:06 hn-dlp kernel: audit: type=1403 audit(1610261581.592:2): auid=4294967295 ses=4294967295 lsm=selinux res=1 Jan 10 07:53:06 hn-dlp systemd[1]: Successfully loaded SELinux policy in 706.184ms. Jan 10 07:53:06 hn-dlp systemd[1]: Relabelled /dev, /run and /sys/fs/cgroup in 27.784ms. Jan 10 07:53:06 hn-dlp systemd[1]: systemd 239 (239-41.el8_3.1) running in system mode. (+PAM +AUDIT +SELINUX +IMA -APPARMOR +SMACK +SYSVINIT +UTMP +LIBCRYPTSETUP +GCRYPT +GNUTLS +ACL +XZ +LZ4 +SECCOMP +BLKID +ELFUTILS +KMOD +IDN2 -IDN +PCRE2 default-hierarchy=legacy) Jan 10 07:53:06 hn-dlp systemd[1]: Detected virtualization kvm. Jan 10 07:53:06 hn-dlp systemd[1]: Detected architecture x86-64. Jan 10 07:53:06 hn-dlp systemd[1]: Set hostname to <hn-dlp.ipa.example.local>. Jan 10 07:53:06 hn-dlp systemd[1]: systemd-journald.service: Succeeded. Jan 10 07:53:06 hn-dlp systemd[1]: initrd-switch-root.service: Succeeded. Jan 10 07:53:06 hn-dlp systemd[1]: Stopped Switch Root. Jan 10 07:53:06 hn-dlp systemd[1]: systemd-journald.service: Service has no hold-off time (RestartSec=0), scheduling restart. Jan 10 07:53:06 hn-dlp systemd[1]: systemd-journald.service: Scheduled restart job, restart counter is at 1. Jan 10 07:53:06 hn-dlp systemd[1]: Stopped Journal Service. Jan 10 07:53:06 hn-dlp kernel: RPC: Registered named UNIX socket transport module. Jan 10 07:53:06 hn-dlp kernel: RPC: Registered udp transport module. Jan 10 07:53:06 hn-dlp kernel: RPC: Registered tcp transport module. Jan 10 07:53:06 hn-dlp kernel: RPC: Registered tcp NFSv4.1 backchannel transport module. Jan 10 07:53:06 hn-dlp kernel: Adding 4194300k swap on /dev/vda5. Priority:-2 extents:1 across:4194300k FS Jan 10 07:53:06 hn-dlp systemd-journald[523]: Journal started Jan 10 07:53:06 hn-dlp systemd-journald[523]: Runtime journal (/run/log/journal/fed2b1b6cbc74355bce5e4c5b7e8359e) is 8.0M, max 65.6M, 57.6M free. Jan 10 07:53:06 hn-dlp systemd-tmpfiles[562]: [/etc/tmpfiles.d/dirsrv-IPA-TECIN-NET.conf:1] Line references path below legacy directory /var/run/, updating /var/run/dirsrv → /run/dirsrv; please update the tmpfiles.d/ drop-in file accordingly. Jan 10 07:53:06 hn-dlp systemd[1]: systemd-vconsole-setup.service: Succeeded. Jan 10 07:53:06 hn-dlp systemd[1]: Started Setup Virtual Console. Jan 10 07:53:06 hn-dlp systemd-tmpfiles[562]: [/usr/lib/tmpfiles.d/krb5-krb5kdc.conf:1] Line references path below legacy directory /var/run/, updating /var/run/krb5kdc → /run/krb5kdc; please update the tmpfiles.d/ drop-in file accordingly. Jan 10 07:53:07 hn-dlp systemd[1]: Started Create Static Device Nodes in /dev. Jan 10 07:53:07 hn-dlp systemd[1]: Starting udev Kernel Device Manager... Jan 10 07:53:08 hn-dlp systemd[1]: Started udev Kernel Device Manager. Jan 10 07:53:08 hn-dlp kernel: piix4_smbus 0000:00:01.3: SMBus Host Controller at 0x700, revision 0 Jan 10 07:53:08 hn-dlp kernel: bochs-drm 0000:00:02.0: vgaarb: deactivate vga console Jan 10 07:53:08 hn-dlp kernel: Console: switching to colour dummy device 80x25 Jan 10 07:53:08 hn-dlp kernel: [drm] Found bochs VGA, ID 0xb0c0. Jan 10 07:53:08 hn-dlp kernel: [drm] Framebuffer size 16384 kB @ 0xfd000000, mmio @ 0xfea50000. Jan 10 07:53:08 hn-dlp kernel: [TTM] Zone kernel: Available graphics memory: 671856 KiB Jan 10 07:53:08 hn-dlp kernel: [TTM] Initializing pool allocator Jan 10 07:53:08 hn-dlp kernel: [TTM] Initializing DMA pool allocator Jan 10 07:53:08 hn-dlp kernel: [drm] Found EDID data blob. Jan 10 07:53:08 hn-dlp kernel: input: PC Speaker as /devices/platform/pcspkr/input/input6 Jan 10 07:53:08 hn-dlp kernel: [drm] Initialized bochs-drm 1.0.0 20130925 for 0000:00:02.0 on minor 0 Jan 10 07:53:08 hn-dlp kernel: fbcon: bochs-drmdrmfb (fb0) is primary device Jan 10 07:53:08 hn-dlp kernel: Console: switching to colour frame buffer device 128x48 Jan 10 07:53:08 hn-dlp kernel: bochs-drm 0000:00:02.0: fb0: bochs-drmdrmfb frame buffer device Jan 10 07:53:08 hn-dlp systemd-udevd[571]: link_config: autonegotiation is unset or enabled, the speed and duplex are not writable. Jan 10 07:53:08 hn-dlp systemd[1]: Started Monitoring of LVM2 mirrors, snapshots etc. using dmeventd or progress polling. Jan 10 07:53:08 hn-dlp systemd-udevd[567]: link_config: autonegotiation is unset or enabled, the speed and duplex are not writable. Jan 10 07:53:09 hn-dlp systemd[1]: Started udev Wait for Complete Device Initialization. Jan 10 07:53:09 hn-dlp systemd[1]: Reached target Local File Systems (Pre). Jan 10 07:53:09 hn-dlp systemd[1]: Mounting /home... Jan 10 07:53:09 hn-dlp systemd[1]: Starting File System Check on /dev/disk/by-uuid/71bcf60c-c03b-4a04-a611-7ff32ed1d58c... Jan 10 07:53:09 hn-dlp systemd[1]: Mounting /var/log... Jan 10 07:53:09 hn-dlp kernel: XFS (vda6): Mounting V5 Filesystem Jan 10 07:53:09 hn-dlp kernel: XFS (vda3): Mounting V5 Filesystem Jan 10 07:53:09 hn-dlp kernel: XFS (vda6): Ending clean mount Jan 10 07:53:09 hn-dlp systemd-fsck[609]: /dev/vda1: clean, 324/65536 files, 79529/262144 blocks Jan 10 07:53:09 hn-dlp systemd[1]: Started File System Check on /dev/disk/by-uuid/71bcf60c-c03b-4a04-a611-7ff32ed1d58c. Jan 10 07:53:09 hn-dlp systemd[1]: Mounting /boot... Jan 10 07:53:09 hn-dlp systemd[1]: Mounted /home. Jan 10 07:53:09 hn-dlp kernel: EXT4-fs (vda1): mounted filesystem with ordered data mode. Opts: (null) Jan 10 07:53:09 hn-dlp systemd[1]: Mounted /boot. Jan 10 07:53:09 hn-dlp kernel: XFS (vda3): Ending clean mount Jan 10 07:53:09 hn-dlp systemd[1]: Mounted /var/log. Jan 10 07:53:09 hn-dlp systemd[1]: Reached target Local File Systems. Jan 10 07:53:09 hn-dlp systemd[1]: Starting Tell Plymouth To Write Out Runtime Data... Jan 10 07:53:09 hn-dlp systemd[1]: Starting Restore /run/initramfs on shutdown... Jan 10 07:53:09 hn-dlp systemd[1]: Starting Import network configuration from initramfs... Jan 10 07:53:09 hn-dlp systemd[1]: Starting Flush Journal to Persistent Storage... Jan 10 07:53:09 hn-dlp systemd[1]: Started Restore /run/initramfs on shutdown. Jan 10 07:53:09 hn-dlp systemd-journald[523]: Runtime journal (/run/log/journal/fed2b1b6cbc74355bce5e4c5b7e8359e) is 8.0M, max 65.6M, 57.6M free. Jan 10 07:53:09 hn-dlp systemd[1]: Started Flush Journal to Persistent Storage. Jan 10 07:53:09 hn-dlp systemd[1]: Received SIGRTMIN+20 from PID 362 (plymouthd). Jan 10 07:53:09 hn-dlp systemd[1]: Started Import network configuration from initramfs. Jan 10 07:53:09 hn-dlp systemd[1]: Starting Create Volatile Files and Directories... Jan 10 07:53:09 hn-dlp systemd[1]: Started Tell Plymouth To Write Out Runtime Data. Jan 10 07:53:09 hn-dlp systemd-tmpfiles[667]: [/etc/tmpfiles.d/dirsrv-IPA-TECIN-NET.conf:1] Line references path below legacy directory /var/run/, updating /var/run/dirsrv → /run/dirsrv; please update the tmpfiles.d/ drop-in file accordingly. Jan 10 07:53:09 hn-dlp systemd-tmpfiles[667]: [/usr/lib/tmpfiles.d/krb5-krb5kdc.conf:1] Line references path below legacy directory /var/run/, updating /var/run/krb5kdc → /run/krb5kdc; please update the tmpfiles.d/ drop-in file accordingly. Jan 10 07:53:10 hn-dlp systemd[1]: Started Create Volatile Files and Directories. Jan 10 07:53:10 hn-dlp systemd[1]: Starting RPC Bind... Jan 10 07:53:10 hn-dlp systemd[1]: Mounting RPC Pipe File System... Jan 10 07:53:10 hn-dlp systemd[1]: Starting Security Auditing Service... Jan 10 07:53:10 hn-dlp systemd[1]: Mounted RPC Pipe File System. Jan 10 07:53:10 hn-dlp systemd[1]: Reached target rpc_pipefs.target. Jan 10 07:53:10 hn-dlp auditd[675]: audit dispatcher initialized with q_depth=400 and 1 active plugins Jan 10 07:53:10 hn-dlp auditd[675]: Init complete, auditd 3.0 listening for events (startup state enable) Jan 10 07:53:10 hn-dlp systemd[1]: Started RPC Bind. Jan 10 07:53:10 hn-dlp augenrules[680]: /sbin/augenrules: No change Jan 10 07:53:10 hn-dlp augenrules[680]: No rules Jan 10 07:53:10 hn-dlp augenrules[680]: enabled 1 Jan 10 07:53:10 hn-dlp augenrules[680]: failure 1 Jan 10 07:53:10 hn-dlp augenrules[680]: pid 675 Jan 10 07:53:10 hn-dlp augenrules[680]: rate_limit 0 Jan 10 07:53:10 hn-dlp augenrules[680]: backlog_limit 8192 Jan 10 07:53:10 hn-dlp augenrules[680]: lost 0 Jan 10 07:53:10 hn-dlp augenrules[680]: backlog 4 Jan 10 07:53:10 hn-dlp augenrules[680]: backlog_wait_time 60000 Jan 10 07:53:10 hn-dlp augenrules[680]: enabled 1 Jan 10 07:53:10 hn-dlp augenrules[680]: failure 1 Jan 10 07:53:10 hn-dlp augenrules[680]: pid 675 Jan 10 07:53:10 hn-dlp augenrules[680]: rate_limit 0 Jan 10 07:53:10 hn-dlp augenrules[680]: backlog_limit 8192 Jan 10 07:53:10 hn-dlp augenrules[680]: lost 0 Jan 10 07:53:10 hn-dlp augenrules[680]: backlog 4 Jan 10 07:53:10 hn-dlp augenrules[680]: backlog_wait_time 60000 Jan 10 07:53:10 hn-dlp augenrules[680]: enabled 1 Jan 10 07:53:10 hn-dlp augenrules[680]: failure 1 Jan 10 07:53:10 hn-dlp augenrules[680]: pid 675 Jan 10 07:53:10 hn-dlp augenrules[680]: rate_limit 0 Jan 10 07:53:10 hn-dlp augenrules[680]: backlog_limit 8192 Jan 10 07:53:10 hn-dlp augenrules[680]: lost 0 Jan 10 07:53:10 hn-dlp augenrules[680]: backlog 4 Jan 10 07:53:10 hn-dlp augenrules[680]: backlog_wait_time 60000 Jan 10 07:53:10 hn-dlp systemd[1]: Started Security Auditing Service. Jan 10 07:53:10 hn-dlp systemd[1]: Starting Update UTMP about System Boot/Shutdown... Jan 10 07:53:10 hn-dlp systemd[1]: Started Update UTMP about System Boot/Shutdown. Jan 10 07:53:10 hn-dlp systemd[1]: Reached target System Initialization. Jan 10 07:53:10 hn-dlp systemd[1]: Listening on Open-iSCSI iscsid Socket. Jan 10 07:53:10 hn-dlp systemd[1]: Listening on Open-iSCSI iscsiuio Socket. Jan 10 07:53:10 hn-dlp systemd[1]: Started dnf makecache --timer. Jan 10 07:53:10 hn-dlp systemd[1]: Listening on D-Bus System Message Bus Socket. Jan 10 07:53:10 hn-dlp systemd[1]: Started daily update of the root trust anchor for DNSSEC. Jan 10 07:53:10 hn-dlp systemd[1]: Started Daily Cleanup of Temporary Directories. Jan 10 07:53:10 hn-dlp systemd[1]: Reached target Timers. Jan 10 07:53:10 hn-dlp systemd[1]: Listening on SSSD Kerberos Cache Manager responder socket. Jan 10 07:53:10 hn-dlp systemd[1]: Reached target Sockets. Jan 10 07:53:10 hn-dlp systemd[1]: Reached target Basic System. Jan 10 07:53:10 hn-dlp systemd[1]: Started libstoragemgmt plug-in server daemon. Jan 10 07:53:10 hn-dlp systemd[1]: Starting NTP client/server... Jan 10 07:53:10 hn-dlp systemd[1]: Starting VDO volume services... Jan 10 07:53:10 hn-dlp systemd[1]: Started irqbalance daemon. Jan 10 07:53:10 hn-dlp systemd[1]: Starting Self Monitoring and Reporting Technology (SMART) Daemon... Jan 10 07:53:10 hn-dlp systemd[1]: Starting Authorization Manager... Jan 10 07:53:10 hn-dlp chronyd[706]: chronyd version 3.5 starting (+CMDMON +NTP +REFCLOCK +RTC +PRIVDROP +SCFILTER +SIGND +ASYNCDNS +SECHASH +IPV6 +DEBUG) Jan 10 07:53:10 hn-dlp systemd[1]: Started Machine Check Exception Logging Daemon. Jan 10 07:53:10 hn-dlp systemd[1]: Started QEMU Guest Agent. Jan 10 07:53:10 hn-dlp systemd[1]: Starting Hardware RNG Entropy Gatherer Wake threshold service... Jan 10 07:53:10 hn-dlp systemd[1]: Started D-Bus System Message Bus. Jan 10 07:53:10 hn-dlp systemd[1]: Starting System Security Services Daemon... Jan 10 07:53:10 hn-dlp systemd[1]: Reached target sshd-keygen.target. Jan 10 07:53:10 hn-dlp systemd[1]: Started Hardware RNG Entropy Gatherer Wake threshold service. Jan 10 07:53:10 hn-dlp systemd[1]: Started Hardware RNG Entropy Gatherer Daemon. Jan 10 07:53:10 hn-dlp chronyd[706]: Frequency 8.877 +/- 0.059 ppm read from /var/lib/chrony/drift Jan 10 07:53:10 hn-dlp chronyd[706]: Using right/UTC timezone to obtain leap second data Jan 10 07:53:10 hn-dlp smartd[703]: smartd 7.1 2020-04-05 r5049 [x86_64-linux-4.18.0-240.1.1.el8_3.x86_64] (local build) Jan 10 07:53:10 hn-dlp smartd[703]: Copyright (C) 2002-19, Bruce Allen, Christian Franke, www.smartmontools.org Jan 10 07:53:10 hn-dlp smartd[703]: Opened configuration file /etc/smartmontools/smartd.conf Jan 10 07:53:10 hn-dlp smartd[703]: Configuration file /etc/smartmontools/smartd.conf was parsed, found DEVICESCAN, scanning devices Jan 10 07:53:10 hn-dlp smartd[703]: In the system's table of devices NO devices found to scan Jan 10 07:53:10 hn-dlp smartd[703]: Monitoring 0 ATA/SATA, 0 SCSI/SAS and 0 NVMe devices Jan 10 07:53:11 hn-dlp sssd[711]: Starting up Jan 10 07:53:12 hn-dlp systemd[1]: Started Self Monitoring and Reporting Technology (SMART) Daemon. Jan 10 07:53:12 hn-dlp polkitd[704]: Started polkitd version 0.115 Jan 10 07:53:12 hn-dlp systemd[1]: Started NTP client/server. Jan 10 07:53:12 hn-dlp be[implicit_files][722]: Starting up Jan 10 07:53:12 hn-dlp be[ipa.example.local][723]: Starting up Jan 10 07:53:12 hn-dlp rngd[715]: Initializing available sources Jan 10 07:53:12 hn-dlp rngd[715]: Failed to init entropy source hwrng Jan 10 07:53:12 hn-dlp rngd[715]: Failed to init entropy source rdrand Jan 10 07:53:13 hn-dlp systemd[1]: Started Authorization Manager. Jan 10 07:53:13 hn-dlp systemd[1]: Starting firewalld - dynamic firewall daemon... Jan 10 07:53:13 hn-dlp nss[738]: Starting up Jan 10 07:53:13 hn-dlp pac[743]: Starting up Jan 10 07:53:13 hn-dlp ifp[740]: Starting up Jan 10 07:53:13 hn-dlp pam[739]: Starting up Jan 10 07:53:13 hn-dlp sudo[742]: Starting up Jan 10 07:53:13 hn-dlp ssh[741]: Starting up Jan 10 07:53:13 hn-dlp systemd[1]: Started System Security Services Daemon. Jan 10 07:53:13 hn-dlp systemd[1]: Reached target User and Group Name Lookups. Jan 10 07:53:13 hn-dlp systemd[1]: Starting Login Service... Jan 10 07:53:13 hn-dlp sssd[711]: Unable to initialize STARTTLS session Jan 10 07:53:13 hn-dlp sssd[711]: Can't contact LDAP server Jan 10 07:53:13 hn-dlp sssd[711]: Failed to bind to server! Jan 10 07:53:13 hn-dlp sssd[711]: Failed to get keytab Jan 10 07:53:14 hn-dlp systemd[1]: Started VDO volume services. Jan 10 07:53:14 hn-dlp rngd[715]: Initializing AES buffer Jan 10 07:53:14 hn-dlp rngd[715]: Enabling JITTER rng support Jan 10 07:53:14 hn-dlp rngd[715]: Initializing entropy source jitter Jan 10 07:53:14 hn-dlp systemd-logind[744]: New seat seat0. Jan 10 07:53:14 hn-dlp systemd-logind[744]: Watching system buttons on /dev/input/event0 (Power Button) Jan 10 07:53:14 hn-dlp systemd-logind[744]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Jan 10 07:53:14 hn-dlp systemd[1]: Started Login Service. Jan 10 07:53:15 hn-dlp systemd[1]: Started firewalld - dynamic firewall daemon. Jan 10 07:53:15 hn-dlp systemd[1]: Reached target Network (Pre). Jan 10 07:53:15 hn-dlp systemd[1]: Starting Network Manager... Jan 10 07:53:15 hn-dlp NetworkManager[762]: <info> [1610261595.3110] NetworkManager (version 1.26.0-12.el8_3) is starting... (for the first time) Jan 10 07:53:15 hn-dlp NetworkManager[762]: <info> [1610261595.3113] Read config: /etc/NetworkManager/NetworkManager.conf (lib: 00-server.conf) (etc: zzz-ipa.conf) Jan 10 07:53:15 hn-dlp systemd[1]: Started Network Manager. Jan 10 07:53:15 hn-dlp systemd[1]: Reached target Network. Jan 10 07:53:15 hn-dlp systemd[1]: Starting Enable periodic update of entitlement certificates.... Jan 10 07:53:15 hn-dlp NetworkManager[762]: <info> [1610261595.3331] bus-manager: acquired D-Bus service "org.freedesktop.NetworkManager" Jan 10 07:53:15 hn-dlp systemd[1]: Starting Logout off all iSCSI sessions on shutdown... Jan 10 07:53:15 hn-dlp systemd[1]: Starting Dynamic System Tuning Daemon... Jan 10 07:53:15 hn-dlp systemd[1]: Starting Certificate monitoring and PKI enrollment... Jan 10 07:53:15 hn-dlp NetworkManager[762]: <info> [1610261595.3717] manager[0x563800b3c000]: monitoring kernel firmware directory '/lib/firmware'. Jan 10 07:53:15 hn-dlp dbus-daemon[710]: [system] Activating via systemd: service name='org.freedesktop.hostname1' unit='dbus-org.freedesktop.hostname1.service' requested by ':1.10' (uid=0 pid=762 comm="/usr/sbin/NetworkManager --no-daemon " label="system_u:system_r:NetworkManager_t:s0") Jan 10 07:53:15 hn-dlp systemd[1]: Starting OpenSSH server daemon... Jan 10 07:53:15 hn-dlp systemd[1]: Starting GSSAPI Proxy Daemon... Jan 10 07:53:15 hn-dlp systemd[1]: Started Puppet agent. Jan 10 07:53:15 hn-dlp systemd[1]: Starting Identity, Policy, Audit... Jan 10 07:53:15 hn-dlp systemd[1]: Started privileged operations for unprivileged applications. Jan 10 07:53:15 hn-dlp systemd[1]: Starting Network Manager Wait Online... Jan 10 07:53:15 hn-dlp systemd[1]: Started Enable periodic update of entitlement certificates.. Jan 10 07:53:15 hn-dlp systemd[1]: Started Logout off all iSCSI sessions on shutdown. Jan 10 07:53:15 hn-dlp systemd[1]: Starting Hostname Service... Jan 10 07:53:15 hn-dlp systemd[1]: Started OpenSSH server daemon. Jan 10 07:53:15 hn-dlp systemd[1]: Started GSSAPI Proxy Daemon. Jan 10 07:53:15 hn-dlp systemd[1]: Starting RPC security service for NFS client and server... Jan 10 07:53:15 hn-dlp firewalld[736]: WARNING: AllowZoneDrifting is enabled. This is considered an insecure configuration option. It will be removed in a future release. Please consider disabling it now. Jan 10 07:53:15 hn-dlp systemd[1]: Started RPC security service for NFS client and server. Jan 10 07:53:15 hn-dlp systemd[1]: Reached target NFS client services. Jan 10 07:53:16 hn-dlp certmonger[773]: 2021-01-10 07:53:16 [773] Changing to root directory. Jan 10 07:53:16 hn-dlp certmonger[773]: 2021-01-10 07:53:16 [773] Obtaining system lock. Jan 10 07:53:16 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.freedesktop.hostname1' Jan 10 07:53:16 hn-dlp systemd[1]: Started Hostname Service. Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.2288] hostname: hostname: using hostnamed Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.2290] hostname: hostname changed from (none) to "hn-dlp.ipa.example.local" Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.2295] dns-mgr[0x563800b1f250]: init: dns=default,systemd-resolved rc-manager=symlink Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.3831] Loaded device plugin: NMTeamFactory (/usr/lib64/NetworkManager/1.26.0-12.el8_3/libnm-device-plugin-team.so) Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.3832] manager: rfkill: Wi-Fi enabled by radio killswitch; enabled by state file Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.3833] manager: rfkill: WWAN enabled by radio killswitch; enabled by state file Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.3834] manager: Networking is enabled by state file Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.3835] dhcp-init: Using DHCP client 'internal' Jan 10 07:53:16 hn-dlp dbus-daemon[710]: [system] Activating via systemd: service name='org.freedesktop.nm_dispatcher' unit='dbus-org.freedesktop.nm-dispatcher.service' requested by ':1.10' (uid=0 pid=762 comm="/usr/sbin/NetworkManager --no-daemon " label="system_u:system_r:NetworkManager_t:s0") Jan 10 07:53:16 hn-dlp systemd[1]: Starting Network Manager Script Dispatcher Service... Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.4990] settings: Loaded settings plugin: ifcfg-rh ("/usr/lib64/NetworkManager/1.26.0-12.el8_3/libnm-settings-plugin-ifcfg-rh.so") Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.4990] settings: Loaded settings plugin: keyfile (internal) Jan 10 07:53:16 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.freedesktop.nm_dispatcher' Jan 10 07:53:16 hn-dlp systemd[1]: Started Network Manager Script Dispatcher Service. Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.6010] device (lo): carrier: link connected Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.6013] manager: (lo): new Generic device (/org/freedesktop/NetworkManager/Devices/1) Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.6024] manager: (ens18): new Ethernet device (/org/freedesktop/NetworkManager/Devices/2) Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.6629] device (ens18): state change: unmanaged -> unavailable (reason 'managed', sys-iface-state: 'external') Jan 10 07:53:16 hn-dlp kernel: IPv6: ADDRCONF(NETDEV_UP): ens18: link is not ready Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.6640] device (ens18): carrier: link connected Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.6773] device (ens18): state change: unavailable -> disconnected (reason 'none', sys-iface-state: 'managed') Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.6783] policy: auto-activating connection 'ens18' (732c5020-1abf-452e-9327-69c985fc1b4a) Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.6792] device (ens18): Activation: starting connection 'ens18' (732c5020-1abf-452e-9327-69c985fc1b4a) Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.6793] device (ens18): state change: disconnected -> prepare (reason 'none', sys-iface-state: 'managed') Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.6798] manager: NetworkManager state is now CONNECTING Jan 10 07:53:16 hn-dlp NetworkManager[762]: <info> [1610261596.6801] device (ens18): state change: prepare -> config (reason 'none', sys-iface-state: 'managed') Jan 10 07:53:17 hn-dlp be[ipa.example.local][723]: Backend is offline Jan 10 07:53:17 hn-dlp certmonger[773]: 2021-01-10 07:53:17 [1007] Token is named "NSS Generic Crypto Services", not "NSS Certificate DB", skipping. Jan 10 07:53:18 hn-dlp systemd[1]: Started Dynamic System Tuning Daemon. Jan 10 07:53:18 hn-dlp NetworkManager[762]: <info> [1610261598.1910] device (ens18): state change: config -> ip-config (reason 'none', sys-iface-state: 'managed') Jan 10 07:53:18 hn-dlp NetworkManager[762]: <info> [1610261598.2050] device (ens18): state change: ip-config -> ip-check (reason 'none', sys-iface-state: 'managed') Jan 10 07:53:18 hn-dlp NetworkManager[762]: <info> [1610261598.2249] device (ens18): state change: ip-check -> secondaries (reason 'none', sys-iface-state: 'managed') Jan 10 07:53:18 hn-dlp NetworkManager[762]: <info> [1610261598.2252] device (ens18): state change: secondaries -> activated (reason 'none', sys-iface-state: 'managed') Jan 10 07:53:18 hn-dlp NetworkManager[762]: <info> [1610261598.2256] manager: NetworkManager state is now CONNECTED_LOCAL Jan 10 07:53:18 hn-dlp NetworkManager[762]: <info> [1610261598.2265] manager: NetworkManager state is now CONNECTED_SITE Jan 10 07:53:18 hn-dlp NetworkManager[762]: <info> [1610261598.2266] policy: set 'ens18' (ens18) as default for IPv4 routing and DNS Jan 10 07:53:18 hn-dlp NetworkManager[762]: <info> [1610261598.2268] device (ens18): Activation: successful, device activated. Jan 10 07:53:18 hn-dlp NetworkManager[762]: <info> [1610261598.2273] manager: NetworkManager state is now CONNECTED_GLOBAL Jan 10 07:53:18 hn-dlp NetworkManager[762]: <info> [1610261598.2279] manager: startup complete Jan 10 07:53:18 hn-dlp systemd[1]: Started Network Manager Wait Online. Jan 10 07:53:18 hn-dlp systemd[1]: Reached target Network is Online. Jan 10 07:53:18 hn-dlp systemd[1]: Reached target Remote File Systems (Pre). Jan 10 07:53:18 hn-dlp systemd[1]: Reached target Remote File Systems. Jan 10 07:53:18 hn-dlp systemd[1]: Starting Permit User Sessions... Jan 10 07:53:18 hn-dlp systemd[1]: Starting Crash recovery kernel arming... Jan 10 07:53:18 hn-dlp systemd[1]: Starting System Logging Service... Jan 10 07:53:18 hn-dlp systemd[1]: Starting Notify NFS peers of a restart... Jan 10 07:53:18 hn-dlp systemd[1]: Started Permit User Sessions. Jan 10 07:53:18 hn-dlp systemd[1]: Started Command Scheduler. Jan 10 07:53:18 hn-dlp sm-notify[1020]: Version 2.3.3 starting Jan 10 07:53:18 hn-dlp systemd[1]: Started Job spooling tools. Jan 10 07:53:18 hn-dlp systemd[1]: Starting Hold until boot process finishes up... Jan 10 07:53:18 hn-dlp systemd[1]: Starting Terminate Plymouth Boot Screen... Jan 10 07:53:18 hn-dlp systemd[1]: Started Notify NFS peers of a restart. Jan 10 07:53:18 hn-dlp systemd[1]: iscsi.service: Unit cannot be reloaded because it is inactive. Jan 10 07:53:18 hn-dlp systemd[1]: Received SIGRTMIN+21 from PID 362 (plymouthd). Jan 10 07:53:18 hn-dlp systemd[1]: Received SIGRTMIN+21 from PID 362 (plymouthd). Jan 10 07:53:18 hn-dlp systemd[1]: Started Hold until boot process finishes up. Jan 10 07:53:18 hn-dlp systemd[1]: Started Terminate Plymouth Boot Screen. Jan 10 07:53:18 hn-dlp systemd[1]: Started Getty on tty1. Jan 10 07:53:18 hn-dlp systemd[1]: Reached target Login Prompts. Jan 10 07:53:18 hn-dlp rsyslogd[1019]: [origin software="rsyslogd" swVersion="8.1911.0-6.el8" x-pid="1019" x-info="https://www.rsyslog.com"] start Jan 10 07:53:18 hn-dlp systemd[1]: Started System Logging Service. Jan 10 07:53:18 hn-dlp certmonger[773]: 2021-01-10 07:53:18 [1096] Token is named "NSS Generic Crypto Services", not "NSS Certificate DB", skipping. Jan 10 07:53:18 hn-dlp rsyslogd[1019]: imjournal: journal files changed, reloading... [v8.1911.0-6.el8 try https://www.rsyslog.com/e/0 ] Jan 10 07:53:19 hn-dlp certmonger[773]: 2021-01-10 07:53:19 [1200] Token is named "NSS Generic Crypto Services", not "NSS Certificate DB", skipping. Jan 10 07:53:20 hn-dlp certmonger[773]: 2021-01-10 07:53:20 [1312] Token is named "NSS Generic Crypto Services", not "NSS Certificate DB", skipping. Jan 10 07:53:20 hn-dlp kdumpctl[1017]: kexec: loaded kdump kernel Jan 10 07:53:20 hn-dlp kdumpctl[1017]: Starting kdump: [OK] Jan 10 07:53:20 hn-dlp systemd[1]: Started Crash recovery kernel arming. Jan 10 07:53:21 hn-dlp certmonger[773]: 2021-01-10 07:53:21 [1316] Token is named "NSS Generic Crypto Services", not "NSS Certificate DB", skipping. Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1320] Token is named "NSS Generic Crypto Services", not "NSS Certificate DB", skipping. Jan 10 07:53:22 hn-dlp systemd[1]: Started Certificate monitoring and PKI enrollment. Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1323] Running enrollment/cadata helper "/usr/libexec/certmonger/ipa-server-guard". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1324] Running enrollment/cadata helper "/usr/libexec/certmonger/ipa-server-guard". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1325] Running enrollment/cadata helper "/usr/libexec/certmonger/ipa-server-guard". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1326] Running enrollment/cadata helper "/usr/libexec/certmonger/ipa-server-guard". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1327] Running enrollment/cadata helper "/usr/libexec/certmonger/ipa-server-guard". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1328] Running enrollment/cadata helper "/usr/libexec/certmonger/ipa-server-guard". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1329] Running enrollment/cadata helper "/usr/libexec/certmonger/ipa-server-guard". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1330] Running enrollment/cadata helper "/usr/libexec/certmonger/ipa-server-guard". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1331] Running enrollment/cadata helper "/usr/libexec/certmonger/certmaster-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1332] Running enrollment/cadata helper "/usr/libexec/certmonger/certmaster-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1333] Running enrollment/cadata helper "/usr/libexec/certmonger/certmaster-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1334] Running enrollment/cadata helper "/usr/libexec/certmonger/certmaster-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1335] Running enrollment/cadata helper "/usr/libexec/certmonger/certmaster-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1336] Running enrollment/cadata helper "/usr/libexec/certmonger/certmaster-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1337] Running enrollment/cadata helper "/usr/libexec/certmonger/certmaster-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1338] Running enrollment/cadata helper "/usr/libexec/certmonger/certmaster-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1339] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-renew-agent-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1340] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-renew-agent-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1341] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-renew-agent-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1342] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-renew-agent-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1343] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-renew-agent-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1344] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-renew-agent-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1345] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-renew-agent-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: Error opening "/etc/httpd/alias/pwdfile.txt": No such file or directory. Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1347] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-renew-agent-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1349] Running enrollment/cadata helper "/usr/libexec/certmonger/local-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1350] Running enrollment/cadata helper "/usr/libexec/certmonger/local-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1351] Running enrollment/cadata helper "/usr/libexec/certmonger/local-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1353] Running enrollment/cadata helper "/usr/libexec/certmonger/local-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1354] Running enrollment/cadata helper "/usr/libexec/certmonger/local-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1355] Running enrollment/cadata helper "/usr/libexec/certmonger/local-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1356] Running enrollment/cadata helper "/usr/libexec/certmonger/local-submit". Jan 10 07:53:22 hn-dlp certmonger[773]: 2021-01-10 07:53:22 [1357] Running enrollment/cadata helper "/usr/libexec/certmonger/local-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1358] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1360] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1364] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1367] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1368] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1369] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1370] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1371] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1372] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1374] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1377] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1378] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1381] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1382] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1385] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1386] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1388] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:23 hn-dlp certmonger[773]: 2021-01-10 07:53:23 [1389] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:24 hn-dlp certmonger[773]: 2021-01-10 07:53:24 [1392] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:24 hn-dlp certmonger[773]: 2021-01-10 07:53:24 [1394] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:24 hn-dlp certmonger[773]: 2021-01-10 07:53:24 [1396] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:24 hn-dlp certmonger[773]: 2021-01-10 07:53:24 [1397] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:24 hn-dlp certmonger[773]: 2021-01-10 07:53:24 [1399] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:24 hn-dlp certmonger[773]: 2021-01-10 07:53:24 [1401] Running enrollment/cadata helper "/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit". Jan 10 07:53:24 hn-dlp certmonger[773]: 2021-01-10 07:53:24 [1405] Certificate "Local Signing Authority" valid for 22999722s. Jan 10 07:53:30 hn-dlp systemd[1]: NetworkManager-dispatcher.service: Succeeded. Jan 10 07:53:34 hn-dlp systemd[1]: Created slice system-dirsrv.slice. Jan 10 07:53:34 hn-dlp systemd[1]: Starting 389 Directory Server IPA-TECIN-NET.... Jan 10 07:53:35 hn-dlp certmonger[773]: Error obtaining initial credentials: Cannot contact any KDC for realm 'IPA.example.local'. Jan 10 07:53:35 hn-dlp certmonger[773]: Error setting up ccache at the client: Cannot contact any KDC for realm 'IPA.example.local'. Jan 10 07:53:36 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 07:53:36 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:36.901224447 +0100] - INFO - slapd_extract_cert - CA CERT NAME: IPA.example.local IPA CA Jan 10 07:53:36 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:36.910995773 +0100] - INFO - slapd_extract_cert - CA CERT NAME: DC=tecin,DC=net,E=info@example.local,CN=TecIn-CA Jan 10 07:53:36 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:36.912636146 +0100] - WARN - Security Initialization - SSL alert: Sending pin request to SVRCore. You may need to run systemd-tty-ask-password-agent to provide the password. Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.154904468 +0100] - INFO - slapd_extract_cert - SERVER CERT NAME: Server-Cert Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.661914226 +0100] - INFO - Security Initialization - SSL info: Enabling default cipher set. Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.662830956 +0100] - INFO - Security Initialization - SSL info: Configured NSS Ciphers Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.663483819 +0100] - INFO - Security Initialization - SSL info: #011TLS_AES_128_GCM_SHA256: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.664175555 +0100] - INFO - Security Initialization - SSL info: #011TLS_CHACHA20_POLY1305_SHA256: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.664869061 +0100] - INFO - Security Initialization - SSL info: #011TLS_AES_256_GCM_SHA384: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.665556443 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.672072547 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.673087592 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.673564231 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.674076444 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.674657896 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.675254499 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.675727498 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.676277924 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.676790779 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.677317918 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.677786403 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.678241327 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.678676943 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.679219518 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.679677289 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_128_CBC_SHA: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.680156732 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.680640412 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_256_CBC_SHA: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.681116972 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_256_CBC_SHA256: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.681617192 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.682184432 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.682617161 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_128_CBC_SHA: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.683127657 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.683630286 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_256_CBC_SHA: enabled Jan 10 07:53:37 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:37.684125794 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_256_CBC_SHA256: enabled Jan 10 07:53:38 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:38.262645041 +0100] - INFO - Security Initialization - slapd_ssl_init2 - Configured SSL version range: min: TLS1.2, max: TLS1.3 Jan 10 07:53:38 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:38.263998279 +0100] - INFO - Security Initialization - slapd_ssl_init2 - NSS adjusted SSL version range: min: TLS1.2, max: TLS1.3 Jan 10 07:53:38 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:38.265438146 +0100] - INFO - main - 389-Directory/1.4.3.8 B2020.357.1921 starting up Jan 10 07:53:38 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:38.266622557 +0100] - INFO - main - Setting the maximum file descriptor limit to: 262144 Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.198914081 +0100] - INFO - PBKDF2_SHA256 - Based on CPU performance, chose 2048 rounds Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.203256660 +0100] - INFO - ldbm_instance_config_cachememsize_set - force a minimal value 512000 Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.209735124 +0100] - INFO - ldbm_instance_config_cachememsize_set - force a minimal value 512000 Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.215191116 +0100] - INFO - ldbm_instance_config_cachememsize_set - force a minimal value 512000 Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.220665194 +0100] - NOTICE - ldbm_back_start - found 1343712k physical memory Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.221627834 +0100] - NOTICE - ldbm_back_start - found 877760k available Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.222453940 +0100] - NOTICE - ldbm_back_start - cache autosizing: db cache: 33592k Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.223198733 +0100] - NOTICE - ldbm_back_start - cache autosizing: userRoot entry cache (3 total): 65536k Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.223958097 +0100] - NOTICE - ldbm_back_start - cache autosizing: userRoot dn cache (3 total): 65536k Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.238920850 +0100] - NOTICE - ldbm_back_start - cache autosizing: ipaca entry cache (3 total): 65536k Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.240340739 +0100] - NOTICE - ldbm_back_start - cache autosizing: ipaca dn cache (3 total): 65536k Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.246260282 +0100] - NOTICE - ldbm_back_start - cache autosizing: changelog entry cache (3 total): 65536k Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.247361711 +0100] - NOTICE - ldbm_back_start - cache autosizing: changelog dn cache (3 total): 65536k Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.252193519 +0100] - NOTICE - ldbm_back_start - total cache size: 430172405 B; Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.624757927 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher AES Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.626200240 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.878987342 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher 3DES Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.880178338 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 07:53:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:39.881119794 +0100] - ERR - attrcrypt_init - All prepared ciphers are not available. Please disable attribute encryption. Jan 10 07:53:40 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:40.211795598 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher AES Jan 10 07:53:40 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:40.212909302 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 07:53:40 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:40.460245344 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher 3DES Jan 10 07:53:40 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:40.461104531 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 07:53:40 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:40.461608152 +0100] - ERR - attrcrypt_init - All prepared ciphers are not available. Please disable attribute encryption. Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.050515270 +0100] - ERR - schema-compat-plugin - scheduled schema-compat-plugin tree scan in about 5 seconds after the server startup! Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.091419389 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=groups,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.092738091 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=computers,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.093327809 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=ng,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.093914988 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target ou=sudoers,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.094479267 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=users,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.094977295 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.095527454 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.096127258 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.096770884 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.097362311 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.097947974 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.098574054 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.099356578 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.099967104 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.100542392 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.101156375 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.108182877 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.109050066 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=tecin,dc=net does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.201638885 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=automember rebuild membership,cn=tasks,cn=config does not exist Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.207076863 +0100] - ERR - cos-plugin - cos_dn_defs_cb - Skipping CoS Definition cn=Password Policy,cn=accounts,dc=ipa,dc=tecin,dc=net--no CoS Templates found, which should be added before the CoS Definition. Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.273840766 +0100] - INFO - slapd_daemon - slapd started. Listening on All Interfaces port 389 for LDAP requests Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.274457111 +0100] - INFO - slapd_daemon - Listening on All Interfaces port 636 for LDAPS requests Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.274905833 +0100] - INFO - slapd_daemon - Listening on /var/run/slapd-IPA-TECIN-NET.socket for LDAPI requests Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.275569685 +0100] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/hn-dlp.ipa.example.local@IPA.example.local] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC for requested realm) Jan 10 07:53:41 hn-dlp systemd[1]: Started 389 Directory Server IPA-TECIN-NET.. Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.318924499 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=caToha-dlp.ipa.example.local" (ha-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.320851603 +0100] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/hn-dlp.ipa.example.local@IPA.example.local] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC for requested realm) Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.321926476 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=meTonf-dlp.ipa.example.local" (nf-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.324434995 +0100] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/hn-dlp.ipa.example.local@IPA.example.local] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC for requested realm) Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.325583117 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=caTonf-dlp.ipa.example.local" (nf-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.326922351 +0100] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/hn-dlp.ipa.example.local@IPA.example.local] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC for requested realm) Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.327854095 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=meToha-dlp.ipa.example.local" (ha-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 07:53:41 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:41.328456674 +0100] - ERR - schema-compat-plugin - schema-compat-plugin tree scan will start in about 5 seconds! Jan 10 07:53:41 hn-dlp systemd[1]: Starting Kerberos 5 KDC... Jan 10 07:53:41 hn-dlp systemd[1]: krb5kdc.service: Can't open PID file /var/run/krb5kdc.pid (yet?) after start: No such file or directory Jan 10 07:53:41 hn-dlp systemd[1]: Started Kerberos 5 KDC. Jan 10 07:53:41 hn-dlp systemd[1]: Starting Kerberos 5 Password-changing and Administration... Jan 10 07:53:42 hn-dlp systemd[1]: Started Kerberos 5 Password-changing and Administration. Jan 10 07:53:42 hn-dlp systemd[1]: Starting Generate rndc key for BIND (DNS)... Jan 10 07:53:42 hn-dlp systemd[1]: named-setup-rndc.service: Succeeded. Jan 10 07:53:42 hn-dlp systemd[1]: Started Generate rndc key for BIND (DNS). Jan 10 07:53:42 hn-dlp systemd[1]: Starting Berkeley Internet Name Domain (DNS) with native PKCS#11... Jan 10 07:53:42 hn-dlp bash[1516]: zone localhost.localdomain/IN: loaded serial 0 Jan 10 07:53:42 hn-dlp bash[1516]: zone localhost/IN: loaded serial 0 Jan 10 07:53:42 hn-dlp bash[1516]: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 0 Jan 10 07:53:42 hn-dlp bash[1516]: zone 1.0.0.127.in-addr.arpa/IN: loaded serial 0 Jan 10 07:53:42 hn-dlp bash[1516]: zone 0.in-addr.arpa/IN: loaded serial 0 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: starting BIND 9.11.20-RedHat-9.11.20-5.el8 (Extended Support Version) <id:f3d1d66> Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: running on Linux x86_64 4.18.0-240.1.1.el8_3.x86_64 #1 SMP Thu Nov 19 17:20:08 UTC 2020 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: built with '--build=x86_64-redhat-linux-gnu' '--host=x86_64-redhat-linux-gnu' '--program-prefix=' '--disable-dependency-tracking' '--prefix=/usr' '--exec-prefix=/usr' '--bindir=/usr/bin' '--sbindir=/usr/sbin' '--sysconfdir=/etc' '--datadir=/usr/share' '--includedir=/usr/include' '--libdir=/usr/lib64' '--libexecdir=/usr/libexec' '--sharedstatedir=/var/lib' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--with-python=/usr/libexec/platform-python' '--with-libtool' '--localstatedir=/var' '--enable-threads' '--enable-ipv6' '--enable-filter-aaaa' '--with-pic' '--disable-static' '--includedir=/usr/include/bind9' '--with-tuning=large' '--with-libidn2' '--enable-openssl-hash' '--with-geoip2' '--enable-native-pkcs11' '--with-pkcs11=/usr/lib64/pkcs11/libsofthsm2.so' '--with-dlopen=yes' '--with-dlz-ldap=yes' '--with-dlz-postgres=yes' '--with-dlz-mysql=yes' '--with-dlz-filesystem=yes' '--with-dlz-bdb=yes' '--with-gssapi=yes' '--disable-isc-spnego' '--with-lmdb=no' '--with-cmocka' '--enable-fixed-rrset' '--with-docbook-xsl=/usr/share/sgml/docbook/xsl-stylesheets' '--enable-full-report' 'build_alias=x86_64-redhat-linux-gnu' 'host_alias=x86_64-redhat-linux-gnu' 'CFLAGS= -O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection' 'LDFLAGS=-Wl,-z,relro -Wl,-z,now -specs=/usr/lib/rpm/redhat/redhat-hardened-ld' 'CPPFLAGS= -DDIG_SIGCHASE' 'PKG_CONFIG_PATH=:/usr/lib64/pkgconfig:/usr/share/pkgconfig' Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: running as: named-pkcs11 -u named -c /etc/named.conf Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: compiled by GCC 8.3.1 20191121 (Red Hat 8.3.1-5) Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: compiled with libxml2 version: 2.9.7 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: linked to libxml2 version: 20907 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: compiled with zlib version: 1.2.11 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: linked to zlib version: 1.2.11 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: threads support is enabled Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: ---------------------------------------------------- Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: BIND 9 is maintained by Internet Systems Consortium, Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: Inc. (ISC), a non-profit 501(c)(3) public-benefit Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: corporation. Support and training for BIND 9 are Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: available at https://www.isc.org/support Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: ---------------------------------------------------- Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: adjusted limit on open files from 262144 to 1048576 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: found 4 CPUs, using 4 worker threads Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: using 3 UDP listeners per interface Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: using up to 21000 sockets Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: loading configuration from '/etc/named.conf' Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: unable to open '/etc/bind.keys'; using built-in keys instead Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: looking for GeoIP2 databases in '/usr/share/GeoIP' Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-Country.mmdb' Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-City.mmdb' Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: using default UDP/IPv4 port range: [32768, 60999] Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: using default UDP/IPv6 port range: [32768, 60999] Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: listening on IPv6 interfaces, port 53 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: listening on IPv4 interface lo, 127.0.0.1#53 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: listening on IPv4 interface ens18, 172.19.187.2#53 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: generating session key for dynamic DNS Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: sizing zone task pool based on 6 zones Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: none:104: 'max-cache-size 90%' - setting to 1180MB (out of 1312MB) Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: set up managed keys zone for view _default, file '/var/named/dynamic/managed-keys.bind' Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: loading DynDB instance 'ipa' driver '/usr/lib64/bind/ldap.so' Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: bind-dyndb-ldap version 11.3 compiled at 16:06:42 Sep 1 2020, compiler 8.3.1 20191121 (Red Hat 8.3.1-5) Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 10.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 16.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 17.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 18.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 19.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 20.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 21.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 22.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 23.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 24.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 25.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 26.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 27.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 28.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 29.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 30.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 31.172.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 168.192.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 64.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 65.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 66.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 67.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 68.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 69.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 70.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 71.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 72.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 73.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 74.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 75.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 76.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 77.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 78.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 79.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 80.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 81.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 82.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 83.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 84.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 85.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 86.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 87.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 88.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 89.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 90.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 91.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 92.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 93.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 94.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 95.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 96.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 97.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 98.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 99.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 100.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 101.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 102.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 103.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 104.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 105.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 106.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 107.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 108.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 109.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 110.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 111.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 112.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 113.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 114.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 115.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 116.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 117.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 118.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 119.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 120.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 121.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 122.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 123.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 124.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 125.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 126.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 127.100.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 127.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 254.169.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 2.0.192.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 100.51.198.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 113.0.203.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 255.255.255.255.IN-ADDR.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: D.F.IP6.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 8.E.F.IP6.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 9.E.F.IP6.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: A.E.F.IP6.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: B.E.F.IP6.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: 8.B.D.0.1.0.0.2.IP6.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: EMPTY.AS112.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: automatic empty zone: HOME.ARPA Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: none:104: 'max-cache-size 90%' - setting to 1180MB (out of 1312MB) Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: configuring command channel from '/etc/rndc.key' Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: command channel listening on 127.0.0.1#953 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: configuring command channel from '/etc/rndc.key' Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: command channel listening on ::1#953 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: managed-keys-zone: journal file is out of date: removing journal file Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: managed-keys-zone: loaded serial 226 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: shutting down automatic empty zones to enable forwarding for domain '.' Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 0.in-addr.arpa/IN: loaded serial 0 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 100.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 1.0.0.127.in-addr.arpa/IN: loaded serial 0 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 101.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 0 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 102.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 104.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 105.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 106.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 107.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 108.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone localhost.localdomain/IN: loaded serial 0 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 109.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 110.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone localhost/IN: loaded serial 0 Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 111.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 112.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 113.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 114.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 115.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 116.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 117.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 118.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 119.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: all zones loaded Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 120.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: running Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 121.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 122.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 123.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 124.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 125.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 126.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 127.100.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 254.169.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 2.0.192.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 100.51.198.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp systemd[1]: Started Berkeley Internet Name Domain (DNS) with native PKCS#11. Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 113.0.203.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 255.255.255.255.IN-ADDR.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp systemd[1]: Reached target Host and Network Name Lookups. Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone D.F.IP6.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 8.E.F.IP6.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 9.E.F.IP6.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone A.E.F.IP6.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone B.E.F.IP6.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone 8.B.D.0.1.0.0.2.IP6.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: zone EMPTY.AS112.ARPA/IN: shutting down Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: LDAP configuration for instance 'ipa' synchronized Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: LDAP data for instance 'ipa' are being synchronized, please ignore message 'all zones loaded' Jan 10 07:53:42 hn-dlp named-pkcs11[1520]: forward zone 'int.example.local': loaded Jan 10 07:53:43 hn-dlp named-pkcs11[1520]: forward zone 'srv.example.local': loaded Jan 10 07:53:43 hn-dlp named-pkcs11[1520]: zone 177.19.172.in-addr.arpa/IN: loaded serial 1610261622 Jan 10 07:53:43 hn-dlp named-pkcs11[1520]: zone 177.19.172.in-addr.arpa/IN: sending notifies (serial 1610261622) Jan 10 07:53:43 hn-dlp named-pkcs11[1520]: zone 187.19.172.in-addr.arpa/IN: sending notifies (serial 1610261622) Jan 10 07:53:43 hn-dlp named-pkcs11[1520]: zone 187.19.172.in-addr.arpa/IN: loaded serial 1610261622 Jan 10 07:53:43 hn-dlp named-pkcs11[1520]: zone 195.19.172.in-addr.arpa/IN: loaded serial 1610261623 Jan 10 07:53:43 hn-dlp named-pkcs11[1520]: zone 197.19.172.in-addr.arpa/IN: loaded serial 1610261622 Jan 10 07:53:43 hn-dlp named-pkcs11[1520]: zone 195.19.172.in-addr.arpa/IN: sending notifies (serial 1610261623) Jan 10 07:53:43 hn-dlp named-pkcs11[1520]: zone ipa.example.local/IN: loaded serial 1610261622 Jan 10 07:53:43 hn-dlp named-pkcs11[1520]: 5 master zones from LDAP instance 'ipa' loaded (5 zones defined, 0 inactive, 0 failed to load) Jan 10 07:53:43 hn-dlp named-pkcs11[1520]: zone ipa.example.local/IN: sending notifies (serial 1610261622) Jan 10 07:53:43 hn-dlp named-pkcs11[1520]: zone 197.19.172.in-addr.arpa/IN: sending notifies (serial 1610261622) Jan 10 07:53:43 hn-dlp systemd[1]: Starting One-time temporary TLS key generation for httpd.service... Jan 10 07:53:43 hn-dlp systemd[1]: httpd-init.service: Succeeded. Jan 10 07:53:43 hn-dlp systemd[1]: Started One-time temporary TLS key generation for httpd.service. Jan 10 07:53:43 hn-dlp systemd[1]: Starting The Apache HTTP Server... Jan 10 07:53:45 hn-dlp ipa-httpd-kdcproxy[1535]: ipa: INFO: KDC proxy enabled Jan 10 07:53:45 hn-dlp ipa-httpd-kdcproxy[1535]: ipa-httpd-kdcproxy: INFO KDC proxy enabled Jan 10 07:53:46 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:46.336330956 +0100] - ERR - schema-compat-plugin - warning: no entries set up under ou=sudoers,dc=ipa,dc=tecin,dc=net Jan 10 07:53:46 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:46.337853184 +0100] - ERR - schema-compat-plugin - warning: no entries set up under cn=ng, cn=compat,dc=ipa,dc=tecin,dc=net Jan 10 07:53:46 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:46.517076600 +0100] - ERR - schema-compat-plugin - warning: no entries set up under cn=computers, cn=compat,dc=ipa,dc=tecin,dc=net Jan 10 07:53:46 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:53:46.518191129 +0100] - ERR - schema-compat-plugin - Finished plugin initialization. Jan 10 07:53:46 hn-dlp systemd[1]: systemd-hostnamed.service: Succeeded. Jan 10 07:53:46 hn-dlp systemd[1]: Started The Apache HTTP Server. Jan 10 07:53:46 hn-dlp systemd[1]: Starting IPA Custodia Service... Jan 10 07:53:46 hn-dlp httpd[1538]: Server configured, listening on: port 443, port 80 Jan 10 07:53:47 hn-dlp ipa-custodia[1549]: 2021-01-10 07:53:47 - custodia - Custodia instance <main> Jan 10 07:53:48 hn-dlp named-pkcs11[1520]: zone 177.19.172.in-addr.arpa/IN: sending notifies (serial 1610261622) Jan 10 07:53:48 hn-dlp named-pkcs11[1520]: zone 187.19.172.in-addr.arpa/IN: sending notifies (serial 1610261622) Jan 10 07:53:48 hn-dlp named-pkcs11[1520]: zone 195.19.172.in-addr.arpa/IN: sending notifies (serial 1610261623) Jan 10 07:53:48 hn-dlp named-pkcs11[1520]: zone 197.19.172.in-addr.arpa/IN: sending notifies (serial 1610261622) Jan 10 07:53:48 hn-dlp named-pkcs11[1520]: zone ipa.example.local/IN: sending notifies (serial 1610261622) Jan 10 07:53:48 hn-dlp ipa-custodia[1549]: 2021-01-10 07:53:48 - server - Serving on Unix socket /run/httpd/ipa-custodia.sock Jan 10 07:53:48 hn-dlp systemd[1]: Started IPA Custodia Service. Jan 10 07:53:48 hn-dlp systemd[1]: Created slice system-pki\x2dtomcatd.slice. Jan 10 07:53:48 hn-dlp systemd[1]: Reached target 389 Directory Server. Jan 10 07:53:48 hn-dlp systemd[1]: Starting PKI Tomcat Server pki-tomcat... Jan 10 07:53:52 hn-dlp named-pkcs11[1520]: managed-keys-zone: Unable to fetch DNSKEY set '.': timed out Jan 10 07:53:54 hn-dlp server[1953]: Java virtual machine used: /usr/lib/jvm/jre-openjdk/bin/java Jan 10 07:53:54 hn-dlp server[1953]: classpath used: /usr/share/tomcat/bin/bootstrap.jar:/usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/ant.jar:/usr/share/java/ant-launcher.jar:/usr/lib/jvm/java/lib/tools.jar Jan 10 07:53:54 hn-dlp server[1953]: main class used: org.apache.catalina.startup.Bootstrap Jan 10 07:53:54 hn-dlp server[1953]: flags used: -Dcom.redhat.fips=false Jan 10 07:53:54 hn-dlp server[1953]: options used: -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Djava.security.manager -Djava.security.policy==/var/lib/pki/pki-tomcat/conf/catalina.policy Jan 10 07:53:54 hn-dlp server[1953]: arguments used: start Jan 10 07:53:55 hn-dlp ipa-pki-wait-running[1954]: pki.client: /usr/libexec/ipa/ipa-pki-wait-running:63: The subsystem in PKIConnection.__init__() has been deprecated (https://www.dogtagpki.org/wiki/PKI_10.8_Python_Changes). Jan 10 07:53:55 hn-dlp ipa-pki-wait-running[1954]: ipa-pki-wait-running: Created connection http://hn-dlp.ipa.example.local:8080/ca Jan 10 07:53:55 hn-dlp ipa-pki-wait-running[1954]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Max retries exceeded with url: /ca/admin/ca/getStatus (Caused by NewConnectionError('<urllib3.connection.HTTPConnection object at 0x7f3ea74d7be0>: Failed to establish a new connection: [Errno 111] Connection refused',)) Jan 10 07:53:56 hn-dlp ipa-pki-wait-running[1954]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Max retries exceeded with url: /ca/admin/ca/getStatus (Caused by NewConnectionError('<urllib3.connection.HTTPConnection object at 0x7f3ea74d7fd0>: Failed to establish a new connection: [Errno 111] Connection refused',)) Jan 10 07:53:57 hn-dlp server[1953]: WARNING: Some of the specified [protocols] are not supported by the SSL engine and have been skipped: [[TLSv1, TLSv1.1]] Jan 10 07:53:58 hn-dlp ipa-pki-wait-running[1954]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 07:54:00 hn-dlp ipa-pki-wait-running[1954]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 07:54:02 hn-dlp ipa-pki-wait-running[1954]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 07:54:04 hn-dlp ipa-pki-wait-running[1954]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 07:54:05 hn-dlp ipa-pki-wait-running[1954]: ipa-pki-wait-running: Success, subsystem ca is running! Jan 10 07:54:05 hn-dlp systemd[1]: Started PKI Tomcat Server pki-tomcat. Jan 10 07:54:05 hn-dlp systemd[1]: Reached target PKI Tomcat Server. Jan 10 07:54:05 hn-dlp systemd[1]: Starting Samba SMB Daemon... Jan 10 07:54:07 hn-dlp smbd[2087]: [2021/01/10 07:54:07.034285, 0] ../../lib/util/become_daemon.c:136(daemon_ready) Jan 10 07:54:07 hn-dlp systemd[1]: Started Samba SMB Daemon. Jan 10 07:54:07 hn-dlp smbd[2087]: daemon_ready: daemon 'smbd' finished starting up and ready to serve connections Jan 10 07:54:07 hn-dlp systemd[1]: Starting Samba Winbind Daemon... Jan 10 07:54:07 hn-dlp winbindd[2095]: [2021/01/10 07:54:07.523549, 0] ../../source3/winbindd/winbindd_cache.c:3205(initialize_winbindd_cache) Jan 10 07:54:07 hn-dlp winbindd[2095]: initialize_winbindd_cache: clearing cache and re-creating with version number 2 Jan 10 07:54:07 hn-dlp winbindd[2095]: [2021/01/10 07:54:07.539835, 0] ../../lib/util/become_daemon.c:136(daemon_ready) Jan 10 07:54:07 hn-dlp winbindd[2095]: daemon_ready: daemon 'winbindd' finished starting up and ready to serve connections Jan 10 07:54:07 hn-dlp systemd[1]: Started Samba Winbind Daemon. Jan 10 07:54:07 hn-dlp systemd[1]: Listening on ipa-otpd socket. Jan 10 07:54:07 hn-dlp systemd[1]: Starting ipa-ods-exporter.socket. Jan 10 07:54:07 hn-dlp systemd[1]: Listening on ipa-ods-exporter.socket. Jan 10 07:54:07 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 07:54:07 hn-dlp systemd[1]: Starting OpenDNSSEC Enforcer daemon... Jan 10 07:54:07 hn-dlp ods-enforcerd[2112]: [engine] running as pid 2112 Jan 10 07:54:07 hn-dlp ods-enforcerd[2112]: [engine] enforcer started Jan 10 07:54:07 hn-dlp ods-enforcerd[2112]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 07:54:07 hn-dlp ods-enforcerd[2112]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 07:54:07 hn-dlp ods-enforcerd[2112]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 07:54:07 hn-dlp ods-enforcerd[2111]: OpenDNSSEC key and signing policy enforcer version 2.1.6 Jan 10 07:54:07 hn-dlp systemd[1]: Started OpenDNSSEC Enforcer daemon. Jan 10 07:54:08 hn-dlp systemd[1]: Started IPA key daemon. Jan 10 07:54:08 hn-dlp ipactl[785]: ipa: INFO: The ipactl command was successful Jan 10 07:54:08 hn-dlp ipactl[785]: Starting Directory Service Jan 10 07:54:08 hn-dlp ipactl[785]: Starting krb5kdc Service Jan 10 07:54:08 hn-dlp ipactl[785]: Starting kadmin Service Jan 10 07:54:08 hn-dlp ipactl[785]: Starting named Service Jan 10 07:54:08 hn-dlp ipactl[785]: Starting httpd Service Jan 10 07:54:08 hn-dlp ipactl[785]: Starting ipa-custodia Service Jan 10 07:54:08 hn-dlp ipactl[785]: Starting pki-tomcatd Service Jan 10 07:54:08 hn-dlp ipactl[785]: Starting smb Service Jan 10 07:54:08 hn-dlp ipactl[785]: Starting winbind Service Jan 10 07:54:08 hn-dlp ipactl[785]: Starting ipa-otpd Service Jan 10 07:54:08 hn-dlp ipactl[785]: Starting ipa-ods-exporter Service Jan 10 07:54:08 hn-dlp ipactl[785]: Starting ods-enforcerd Service Jan 10 07:54:08 hn-dlp ipactl[785]: Starting ipa-dnskeysyncd Service Jan 10 07:54:09 hn-dlp systemd[1]: Started Identity, Policy, Audit. Jan 10 07:54:09 hn-dlp systemd[1]: Reached target Multi-User System. Jan 10 07:54:09 hn-dlp systemd[1]: Starting Update UTMP about System Runlevel Changes... Jan 10 07:54:09 hn-dlp systemd[1]: systemd-update-utmp-runlevel.service: Succeeded. Jan 10 07:54:09 hn-dlp systemd[1]: Started Update UTMP about System Runlevel Changes. Jan 10 07:54:09 hn-dlp systemd[1]: Startup finished in 768ms (kernel) + 8.277s (initrd) + 1min 8.341s (userspace) = 1min 17.387s. Jan 10 07:54:13 hn-dlp platform-python[2108]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 07:54:13 hn-dlp platform-python[2108]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 07:54:13 hn-dlp platform-python[2108]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 07:54:13 hn-dlp ipa-dnskeysyncd[2121]: ipa-dnskeysyncd: INFO LDAP bind... Jan 10 07:54:13 hn-dlp ipa-dnskeysyncd[2121]: ipa-dnskeysyncd: INFO Commencing sync process Jan 10 07:54:13 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2108]: new replica keys in LDAP: set() Jan 10 07:54:13 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2108]: obsolete replica keys in local HSM: set() Jan 10 07:54:13 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2108]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 07:54:13 hn-dlp ipa-dnskeysyncd[2121]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-eeae1a850283edc8a00566c3dee263f0,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 07:54:13 hn-dlp ipa-dnskeysyncd[2121]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c04eba886f71eaf6942e4187a168530d,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 07:54:13 hn-dlp ipa-dnskeysyncd[2121]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-795ec7e363b4e831c99bc7751b006b8e,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 07:54:13 hn-dlp ipa-dnskeysyncd[2121]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-b16ee269a69c62ab190b78039c574e4b,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 07:54:13 hn-dlp ipa-dnskeysyncd[2121]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c5b715f14457ccb40f60e224b2220d7f,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 07:54:13 hn-dlp ipa-dnskeysyncd[2121]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-6e817263927b3519a7b5757e90ba5cfc,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 07:54:13 hn-dlp ipa-dnskeysyncd[2121]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100539Z-49de8f2954963b5779491cdacc9232c5,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 07:54:13 hn-dlp ipa-dnskeysyncd[2121]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-3e7a2e5aaa81fd5f1608f7824dd42b8e,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 07:54:13 hn-dlp ipa-dnskeysyncd[2121]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100552Z-2ff98d67ad4fd9c22202c132ec0d4141,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 07:54:13 hn-dlp ipa-dnskeysyncd[2121]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100556Z-708bc11ade0ce1fe2b4b061e80cc0035,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 07:54:13 hn-dlp ipa-dnskeysyncd[2121]: ipaserver.dnssec.keysyncer: INFO Initial LDAP dump is done, sychronizing with ODS and BIND Jan 10 07:54:13 hn-dlp ipa-ods-exporter[2108]: Traceback (most recent call last): Jan 10 07:54:13 hn-dlp ipa-ods-exporter[2108]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 07:54:13 hn-dlp ipa-ods-exporter[2108]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 07:54:13 hn-dlp ipa-ods-exporter[2108]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 07:54:13 hn-dlp ipa-ods-exporter[2108]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 07:54:13 hn-dlp ipa-ods-exporter[2108]: KeyError: 'popitem(): dictionary is empty' Jan 10 07:54:13 hn-dlp ods-enforcerd[2112]: INFO: The XML in /etc/opendnssec/zonelist.xml.new is valid Jan 10 07:54:13 hn-dlp ods-enforcerd[2112]: [zonelist_export_cmd] zonelist exported to /etc/opendnssec/zonelist.xml successfully Jan 10 07:54:13 hn-dlp ipa-dnskeysyncd[2121]: ipaserver.dnssec.odsmgr: INFO Zones removed from LDAP: [] Jan 10 07:54:13 hn-dlp ipa-dnskeysyncd[2121]: ipaserver.dnssec.odsmgr: INFO Zones added to LDAP: [] Jan 10 07:54:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 07:54:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 07:54:34 hn-dlp be[ipa.example.local][723]: Backend is online Jan 10 07:54:38 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.48' (uid=0 pid=677 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 07:54:38 hn-dlp dbus-daemon[2148]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 07:54:40 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 07:54:41 hn-dlp setroubleshoot[2148]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der Jan 10 07:54:42 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.51' (uid=995 pid=2148 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 07:54:42 hn-dlp dbus-daemon[2161]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 07:54:44 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 07:54:48 hn-dlp setroubleshoot[2148]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 07:54:48 hn-dlp setroubleshoot[2148]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-050000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 07:54:57 hn-dlp chronyd[706]: Selected source 79.133.44.138 Jan 10 07:54:57 hn-dlp chronyd[706]: System clock TAI offset set to 37 seconds Jan 10 07:55:09 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.48' (uid=0 pid=677 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 07:55:09 hn-dlp dbus-daemon[2179]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 07:55:11 hn-dlp named-pkcs11[1520]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 07:55:11 hn-dlp named-pkcs11[1520]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 07:55:13 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 07:55:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 07:55:14 hn-dlp setroubleshoot[2179]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der Jan 10 07:55:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 1. Jan 10 07:55:14 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 07:55:14 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 07:55:14 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.56' (uid=995 pid=2179 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 07:55:14 hn-dlp dbus-daemon[2193]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 07:55:15 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 07:55:20 hn-dlp setroubleshoot[2179]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 07:55:20 hn-dlp setroubleshoot[2179]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-050000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 07:55:23 hn-dlp platform-python[2186]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 07:55:23 hn-dlp platform-python[2186]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 07:55:23 hn-dlp platform-python[2186]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 07:55:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2186]: new replica keys in LDAP: set() Jan 10 07:55:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2186]: obsolete replica keys in local HSM: set() Jan 10 07:55:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2186]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 07:55:23 hn-dlp ipa-ods-exporter[2186]: Traceback (most recent call last): Jan 10 07:55:23 hn-dlp ipa-ods-exporter[2186]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 07:55:23 hn-dlp ipa-ods-exporter[2186]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 07:55:23 hn-dlp ipa-ods-exporter[2186]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 07:55:23 hn-dlp ipa-ods-exporter[2186]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 07:55:23 hn-dlp ipa-ods-exporter[2186]: KeyError: 'popitem(): dictionary is empty' Jan 10 07:55:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 07:55:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 07:55:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 07:56:03 hn-dlp chronyd[706]: Selected source 78.46.92.194 Jan 10 07:56:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 07:56:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 2. Jan 10 07:56:24 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 07:56:24 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 07:56:28 hn-dlp platform-python[2248]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 07:56:28 hn-dlp platform-python[2248]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 07:56:28 hn-dlp platform-python[2248]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 07:56:28 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2248]: new replica keys in LDAP: set() Jan 10 07:56:28 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2248]: obsolete replica keys in local HSM: set() Jan 10 07:56:28 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2248]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 07:56:28 hn-dlp ipa-ods-exporter[2248]: Traceback (most recent call last): Jan 10 07:56:28 hn-dlp ipa-ods-exporter[2248]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 07:56:28 hn-dlp ipa-ods-exporter[2248]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 07:56:28 hn-dlp ipa-ods-exporter[2248]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 07:56:28 hn-dlp ipa-ods-exporter[2248]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 07:56:28 hn-dlp ipa-ods-exporter[2248]: KeyError: 'popitem(): dictionary is empty' Jan 10 07:56:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 07:56:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 07:56:42 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.48' (uid=0 pid=677 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 07:56:42 hn-dlp dbus-daemon[2257]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 07:56:45 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 07:56:45 hn-dlp setroubleshoot[2257]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der Jan 10 07:56:46 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.63' (uid=995 pid=2257 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 07:56:46 hn-dlp dbus-daemon[2269]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 07:56:46 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 07:56:48 hn-dlp setroubleshoot[2257]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 07:56:48 hn-dlp setroubleshoot[2257]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-050000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 07:57:11 hn-dlp named-pkcs11[1520]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 07:57:11 hn-dlp named-pkcs11[1520]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 07:57:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 07:57:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 3. Jan 10 07:57:28 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 07:57:28 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 07:57:31 hn-dlp platform-python[2274]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 07:57:31 hn-dlp platform-python[2274]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 07:57:31 hn-dlp platform-python[2274]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 07:57:31 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2274]: new replica keys in LDAP: set() Jan 10 07:57:31 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2274]: obsolete replica keys in local HSM: set() Jan 10 07:57:31 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2274]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 07:57:31 hn-dlp ipa-ods-exporter[2274]: Traceback (most recent call last): Jan 10 07:57:31 hn-dlp ipa-ods-exporter[2274]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 07:57:31 hn-dlp ipa-ods-exporter[2274]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 07:57:31 hn-dlp ipa-ods-exporter[2274]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 07:57:31 hn-dlp ipa-ods-exporter[2274]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 07:57:31 hn-dlp ipa-ods-exporter[2274]: KeyError: 'popitem(): dictionary is empty' Jan 10 07:57:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 07:57:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 07:57:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 07:58:12 hn-dlp chronyd[706]: Selected source 79.133.44.138 Jan 10 07:58:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 07:58:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 4. Jan 10 07:58:31 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 07:58:31 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 07:58:34 hn-dlp platform-python[2349]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 07:58:34 hn-dlp platform-python[2349]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 07:58:34 hn-dlp platform-python[2349]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 07:58:34 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2349]: new replica keys in LDAP: set() Jan 10 07:58:34 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2349]: obsolete replica keys in local HSM: set() Jan 10 07:58:34 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2349]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 07:58:34 hn-dlp ipa-ods-exporter[2349]: Traceback (most recent call last): Jan 10 07:58:34 hn-dlp ipa-ods-exporter[2349]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 07:58:34 hn-dlp ipa-ods-exporter[2349]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 07:58:34 hn-dlp ipa-ods-exporter[2349]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 07:58:34 hn-dlp ipa-ods-exporter[2349]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 07:58:34 hn-dlp ipa-ods-exporter[2349]: KeyError: 'popitem(): dictionary is empty' Jan 10 07:58:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 07:58:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 07:58:43 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.48' (uid=0 pid=677 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 07:58:43 hn-dlp dbus-daemon[2358]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 07:58:44 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 07:58:44 hn-dlp setroubleshoot[2358]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der Jan 10 07:58:44 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.71' (uid=995 pid=2358 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 07:58:44 hn-dlp dbus-daemon[2370]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 07:58:45 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 07:58:46 hn-dlp setroubleshoot[2358]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 07:58:46 hn-dlp setroubleshoot[2358]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-050000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 07:59:12 hn-dlp named-pkcs11[1520]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 07:59:12 hn-dlp named-pkcs11[1520]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 07:59:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 07:59:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 5. Jan 10 07:59:34 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 07:59:34 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 07:59:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 07:59:37 hn-dlp platform-python[2376]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 07:59:37 hn-dlp platform-python[2376]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 07:59:37 hn-dlp platform-python[2376]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 07:59:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2376]: new replica keys in LDAP: set() Jan 10 07:59:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2376]: obsolete replica keys in local HSM: set() Jan 10 07:59:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2376]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 07:59:38 hn-dlp ipa-ods-exporter[2376]: Traceback (most recent call last): Jan 10 07:59:38 hn-dlp ipa-ods-exporter[2376]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 07:59:38 hn-dlp ipa-ods-exporter[2376]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 07:59:38 hn-dlp ipa-ods-exporter[2376]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 07:59:38 hn-dlp ipa-ods-exporter[2376]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 07:59:38 hn-dlp ipa-ods-exporter[2376]: KeyError: 'popitem(): dictionary is empty' Jan 10 07:59:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 07:59:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 07:59:44 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:59:44.842278192 +0100] - INFO - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=caTonf-dlp.ipa.example.local" (nf-dlp:389): Replication bind with GSSAPI auth resumed Jan 10 07:59:45 hn-dlp ns-slapd[1450]: [10/Jan/2021:07:59:45.082543402 +0100] - INFO - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=meTonf-dlp.ipa.example.local" (nf-dlp:389): Replication bind with GSSAPI auth resumed Jan 10 07:59:57 hn-dlp named-pkcs11[1520]: client @0x7fedc1874720 172.19.186.212#54589 (187.19.172.in-addr.arpa): transfer of '187.19.172.in-addr.arpa/IN': AXFR-style IXFR started (serial 1610261622) Jan 10 07:59:57 hn-dlp named-pkcs11[1520]: client @0x7fedc1874720 172.19.186.212#54589 (187.19.172.in-addr.arpa): transfer of '187.19.172.in-addr.arpa/IN': AXFR-style IXFR ended Jan 10 07:59:57 hn-dlp named-pkcs11[1520]: client @0x7fedb0027b90 172.19.186.212#54590 (177.19.172.in-addr.arpa): transfer of '177.19.172.in-addr.arpa/IN': AXFR-style IXFR started (serial 1610261622) Jan 10 07:59:57 hn-dlp named-pkcs11[1520]: client @0x7fedb0027b90 172.19.186.212#54590 (177.19.172.in-addr.arpa): transfer of '177.19.172.in-addr.arpa/IN': AXFR-style IXFR ended Jan 10 07:59:57 hn-dlp named-pkcs11[1520]: client @0x7fedc0118410 172.19.186.212#54587 (ipa.example.local): transfer of 'ipa.example.local/IN': AXFR-style IXFR started (serial 1610261622) Jan 10 07:59:57 hn-dlp named-pkcs11[1520]: client @0x7fedc0118410 172.19.186.212#54587 (ipa.example.local): transfer of 'ipa.example.local/IN': AXFR-style IXFR ended Jan 10 07:59:57 hn-dlp named-pkcs11[1520]: client @0x7fedc0126fe0 172.19.186.212#54588 (197.19.172.in-addr.arpa): transfer of '197.19.172.in-addr.arpa/IN': AXFR-style IXFR started (serial 1610261622) Jan 10 07:59:57 hn-dlp named-pkcs11[1520]: client @0x7fedc0126fe0 172.19.186.212#54588 (197.19.172.in-addr.arpa): transfer of '197.19.172.in-addr.arpa/IN': AXFR-style IXFR ended Jan 10 08:00:00 hn-dlp named-pkcs11[1520]: no valid RRSIG resolving '168.192.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 08:00:00 hn-dlp named-pkcs11[1520]: no valid DS resolving '2.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:00 hn-dlp named-pkcs11[1520]: validating 4.133.168.192.in-addr.arpa/PTR: bad cache hit (168.192.in-addr.arpa/DS) Jan 10 08:00:00 hn-dlp named-pkcs11[1520]: broken trust chain resolving '4.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:00 hn-dlp named-pkcs11[1520]: validating 3.133.168.192.in-addr.arpa/PTR: bad cache hit (168.192.in-addr.arpa/DS) Jan 10 08:00:00 hn-dlp named-pkcs11[1520]: broken trust chain resolving '3.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:02 hn-dlp named-pkcs11[1520]: validating 104.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:02 hn-dlp named-pkcs11[1520]: broken trust chain resolving '104.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:02 hn-dlp named-pkcs11[1520]: validating 109.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:02 hn-dlp named-pkcs11[1520]: broken trust chain resolving '109.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:02 hn-dlp named-pkcs11[1520]: validating 110.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:02 hn-dlp named-pkcs11[1520]: broken trust chain resolving '110.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:02 hn-dlp named-pkcs11[1520]: validating 113.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:02 hn-dlp named-pkcs11[1520]: broken trust chain resolving '113.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:02 hn-dlp named-pkcs11[1520]: validating 191.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:02 hn-dlp named-pkcs11[1520]: broken trust chain resolving '191.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 192.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '192.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 203.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '203.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 254.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '254.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 104.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '104.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 171.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '171.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 173.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '173.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 183.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '183.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 204.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '204.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 213.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '213.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 216.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '216.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 217.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '217.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 1.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '1.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 5.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '5.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 14.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '14.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 15.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '15.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 1.171.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '1.171.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: validating 2.171.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '2.171.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: validating 100.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: broken trust chain resolving '100.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: validating 103.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: broken trust chain resolving '103.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: validating 254.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: broken trust chain resolving '254.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: validating 104.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: broken trust chain resolving '104.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: validating 107.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: broken trust chain resolving '107.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: validating 254.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: broken trust chain resolving '254.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: validating 5.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: broken trust chain resolving '5.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: validating 11.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: broken trust chain resolving '11.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: validating 100.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: broken trust chain resolving '100.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: validating 254.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:00:04 hn-dlp named-pkcs11[1520]: broken trust chain resolving '254.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:00:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:00:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 6. Jan 10 08:00:38 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:00:38 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:00:41 hn-dlp platform-python[2386]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:00:41 hn-dlp platform-python[2386]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:00:41 hn-dlp platform-python[2386]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:00:41 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2386]: new replica keys in LDAP: set() Jan 10 08:00:41 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2386]: obsolete replica keys in local HSM: set() Jan 10 08:00:41 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2386]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:00:41 hn-dlp ipa-ods-exporter[2386]: Traceback (most recent call last): Jan 10 08:00:41 hn-dlp ipa-ods-exporter[2386]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:00:41 hn-dlp ipa-ods-exporter[2386]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:00:41 hn-dlp ipa-ods-exporter[2386]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:00:41 hn-dlp ipa-ods-exporter[2386]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:00:41 hn-dlp ipa-ods-exporter[2386]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:00:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:00:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:00:42 hn-dlp systemd[1]: Created slice system-user\x2druntime\x2ddir.slice. Jan 10 08:00:42 hn-dlp systemd[1]: Created slice User Slice of UID 2002. Jan 10 08:00:42 hn-dlp systemd[1]: Started /run/user/2002 mount wrapper. Jan 10 08:00:42 hn-dlp systemd[1]: Starting User Manager for UID 2002... Jan 10 08:00:42 hn-dlp systemd[1]: Started Session 1 of user svcforeman. Jan 10 08:00:42 hn-dlp systemd-logind[744]: New session 1 of user svcforeman. Jan 10 08:00:42 hn-dlp systemd[2401]: Started Mark boot as successful after the user session has run 2 minutes. Jan 10 08:00:42 hn-dlp systemd[2401]: Starting D-Bus User Message Bus Socket. Jan 10 08:00:42 hn-dlp systemd[2401]: Reached target Timers. Jan 10 08:00:42 hn-dlp systemd[2401]: Reached target Paths. Jan 10 08:00:42 hn-dlp systemd[2401]: Listening on D-Bus User Message Bus Socket. Jan 10 08:00:42 hn-dlp systemd[2401]: Reached target Sockets. Jan 10 08:00:42 hn-dlp systemd[2401]: Reached target Basic System. Jan 10 08:00:42 hn-dlp systemd[2401]: Reached target Default. Jan 10 08:00:42 hn-dlp systemd[2401]: Startup finished in 217ms. Jan 10 08:00:42 hn-dlp systemd[1]: Started User Manager for UID 2002. Jan 10 08:00:45 hn-dlp platform-python[2564]: ansible-setup Invoked with gather_timeout=10 gather_subset=['all'] filter=* fact_path=/etc/ansible/facts.d Jan 10 08:01:00 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.48' (uid=0 pid=677 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 08:01:00 hn-dlp dbus-daemon[2670]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 08:01:01 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 08:01:01 hn-dlp setroubleshoot[2670]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der Jan 10 08:01:01 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.89' (uid=995 pid=2670 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 08:01:01 hn-dlp dbus-daemon[2694]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 08:01:02 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 08:01:03 hn-dlp setroubleshoot[2670]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 08:01:03 hn-dlp setroubleshoot[2670]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-050000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 08:01:05 hn-dlp setroubleshoot[2670]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der Jan 10 08:01:06 hn-dlp setroubleshoot[2670]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 08:01:06 hn-dlp setroubleshoot[2670]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-050000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 08:01:12 hn-dlp named-pkcs11[1520]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:01:12 hn-dlp named-pkcs11[1520]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:01:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:01:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:01:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 7. Jan 10 08:01:42 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:01:42 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:01:46 hn-dlp platform-python[2704]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:01:46 hn-dlp platform-python[2704]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:01:46 hn-dlp platform-python[2704]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:01:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2704]: new replica keys in LDAP: set() Jan 10 08:01:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2704]: obsolete replica keys in local HSM: set() Jan 10 08:01:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2704]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 08:01:46 hn-dlp ipa-ods-exporter[2704]: Traceback (most recent call last): Jan 10 08:01:46 hn-dlp ipa-ods-exporter[2704]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:01:46 hn-dlp ipa-ods-exporter[2704]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:01:46 hn-dlp ipa-ods-exporter[2704]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:01:46 hn-dlp ipa-ods-exporter[2704]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:01:46 hn-dlp ipa-ods-exporter[2704]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:01:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:01:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:01:51 hn-dlp systemd[1]: session-1.scope: Succeeded. Jan 10 08:01:51 hn-dlp systemd-logind[744]: Session 1 logged out. Waiting for processes to exit. Jan 10 08:01:51 hn-dlp systemd-logind[744]: Removed session 1. Jan 10 08:01:51 hn-dlp systemd[1]: Stopping User Manager for UID 2002... Jan 10 08:01:51 hn-dlp systemd[2401]: Stopped target Default. Jan 10 08:01:51 hn-dlp systemd[2401]: Stopped target Basic System. Jan 10 08:01:51 hn-dlp systemd[2401]: Stopped target Sockets. Jan 10 08:01:51 hn-dlp systemd[2401]: Stopped target Timers. Jan 10 08:01:51 hn-dlp systemd[2401]: grub-boot-success.timer: Succeeded. Jan 10 08:01:51 hn-dlp systemd[2401]: Stopped Mark boot as successful after the user session has run 2 minutes. Jan 10 08:01:51 hn-dlp systemd[2401]: Stopped target Paths. Jan 10 08:01:51 hn-dlp systemd[2401]: dbus.socket: Succeeded. Jan 10 08:01:51 hn-dlp systemd[2401]: Closed D-Bus User Message Bus Socket. Jan 10 08:01:51 hn-dlp systemd[2401]: Reached target Shutdown. Jan 10 08:01:51 hn-dlp systemd[2401]: Starting Exit the Session... Jan 10 08:01:51 hn-dlp systemd[1]: user@2002.service: Succeeded. Jan 10 08:01:51 hn-dlp systemd[1]: Stopped User Manager for UID 2002. Jan 10 08:01:51 hn-dlp systemd[1]: Stopping /run/user/2002 mount wrapper... Jan 10 08:01:51 hn-dlp systemd[1]: Removed slice User Slice of UID 2002. Jan 10 08:01:51 hn-dlp systemd[1]: run-user-2002.mount: Succeeded. Jan 10 08:01:51 hn-dlp systemd[1]: user-runtime-dir@2002.service: Succeeded. Jan 10 08:01:51 hn-dlp systemd[1]: Stopped /run/user/2002 mount wrapper. Jan 10 08:01:57 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.48' (uid=0 pid=677 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 08:01:57 hn-dlp dbus-daemon[2723]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 08:01:58 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 08:01:58 hn-dlp setroubleshoot[2723]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der Jan 10 08:01:59 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.96' (uid=995 pid=2723 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 08:01:59 hn-dlp dbus-daemon[2736]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 08:01:59 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 08:02:00 hn-dlp setroubleshoot[2723]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 08:02:00 hn-dlp setroubleshoot[2723]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-050000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 08:02:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:02:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 8. Jan 10 08:02:46 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:02:46 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:02:50 hn-dlp platform-python[2741]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:02:50 hn-dlp platform-python[2741]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:02:50 hn-dlp platform-python[2741]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:02:50 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2741]: new replica keys in LDAP: set() Jan 10 08:02:50 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2741]: obsolete replica keys in local HSM: set() Jan 10 08:02:50 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2741]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 08:02:50 hn-dlp ipa-ods-exporter[2741]: Traceback (most recent call last): Jan 10 08:02:50 hn-dlp ipa-ods-exporter[2741]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:02:50 hn-dlp ipa-ods-exporter[2741]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:02:50 hn-dlp ipa-ods-exporter[2741]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:02:50 hn-dlp ipa-ods-exporter[2741]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:02:50 hn-dlp ipa-ods-exporter[2741]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:02:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:02:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:02:55 hn-dlp systemd[1]: Starting dnf makecache... Jan 10 08:02:59 hn-dlp dnf[2749]: Updating Subscription Management repositories. Jan 10 08:03:00 hn-dlp dnf[2749]: Metadata cache refreshed recently. Jan 10 08:03:00 hn-dlp systemd[1]: dnf-makecache.service: Succeeded. Jan 10 08:03:00 hn-dlp systemd[1]: Started dnf makecache. Jan 10 08:03:05 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.48' (uid=0 pid=677 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 08:03:05 hn-dlp dbus-daemon[2755]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 08:03:06 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 08:03:06 hn-dlp setroubleshoot[2755]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der Jan 10 08:03:06 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.103' (uid=995 pid=2755 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 08:03:06 hn-dlp dbus-daemon[2768]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 08:03:07 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 08:03:08 hn-dlp setroubleshoot[2755]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 08:03:08 hn-dlp setroubleshoot[2755]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-050000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-050000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 08:03:12 hn-dlp named-pkcs11[1520]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:03:12 hn-dlp named-pkcs11[1520]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:03:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:03:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:03:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 9. Jan 10 08:03:50 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:03:50 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:03:53 hn-dlp platform-python[2772]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:03:53 hn-dlp platform-python[2772]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:03:53 hn-dlp platform-python[2772]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:03:54 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2772]: new replica keys in LDAP: set() Jan 10 08:03:54 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2772]: obsolete replica keys in local HSM: set() Jan 10 08:03:54 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2772]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 08:03:54 hn-dlp ipa-ods-exporter[2772]: Traceback (most recent call last): Jan 10 08:03:54 hn-dlp ipa-ods-exporter[2772]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:03:54 hn-dlp ipa-ods-exporter[2772]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:03:54 hn-dlp ipa-ods-exporter[2772]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:03:54 hn-dlp ipa-ods-exporter[2772]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:03:54 hn-dlp ipa-ods-exporter[2772]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:03:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:03:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:04:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:04:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 10. Jan 10 08:04:54 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:04:54 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:04:56 hn-dlp platform-python[2781]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:04:56 hn-dlp platform-python[2781]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:04:56 hn-dlp platform-python[2781]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:04:57 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2781]: new replica keys in LDAP: set() Jan 10 08:04:57 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2781]: obsolete replica keys in local HSM: set() Jan 10 08:04:57 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2781]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 08:04:57 hn-dlp ipa-ods-exporter[2781]: Traceback (most recent call last): Jan 10 08:04:57 hn-dlp ipa-ods-exporter[2781]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:04:57 hn-dlp ipa-ods-exporter[2781]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:04:57 hn-dlp ipa-ods-exporter[2781]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:04:57 hn-dlp ipa-ods-exporter[2781]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:04:57 hn-dlp ipa-ods-exporter[2781]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:04:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:04:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:05:12 hn-dlp named-pkcs11[1520]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 08:05:12 hn-dlp named-pkcs11[1520]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:05:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:05:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:05:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 11. Jan 10 08:05:57 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:05:57 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:06:00 hn-dlp platform-python[2789]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:06:00 hn-dlp platform-python[2789]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:06:00 hn-dlp platform-python[2789]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:06:00 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2789]: new replica keys in LDAP: set() Jan 10 08:06:00 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2789]: obsolete replica keys in local HSM: set() Jan 10 08:06:00 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2789]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 08:06:00 hn-dlp ipa-ods-exporter[2789]: Traceback (most recent call last): Jan 10 08:06:00 hn-dlp ipa-ods-exporter[2789]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:06:00 hn-dlp ipa-ods-exporter[2789]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:06:00 hn-dlp ipa-ods-exporter[2789]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:06:00 hn-dlp ipa-ods-exporter[2789]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:06:00 hn-dlp ipa-ods-exporter[2789]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:06:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:06:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:06:54 hn-dlp systemd[1]: Created slice User Slice of UID 0. Jan 10 08:06:54 hn-dlp systemd[1]: Started /run/user/0 mount wrapper. Jan 10 08:06:54 hn-dlp systemd[1]: Starting User Manager for UID 0... Jan 10 08:06:54 hn-dlp systemd-logind[744]: New session 3 of user root. Jan 10 08:06:54 hn-dlp systemd[1]: Started Session 3 of user root. Jan 10 08:06:55 hn-dlp systemd[2804]: Reached target Timers. Jan 10 08:06:55 hn-dlp systemd[2804]: Starting D-Bus User Message Bus Socket. Jan 10 08:06:55 hn-dlp systemd[2804]: Reached target Paths. Jan 10 08:06:55 hn-dlp systemd[2804]: Listening on D-Bus User Message Bus Socket. Jan 10 08:06:55 hn-dlp systemd[2804]: Reached target Sockets. Jan 10 08:06:55 hn-dlp systemd[2804]: Reached target Basic System. Jan 10 08:06:55 hn-dlp systemd[2804]: Reached target Default. Jan 10 08:06:55 hn-dlp systemd[2804]: Startup finished in 108ms. Jan 10 08:06:55 hn-dlp systemd[1]: Started User Manager for UID 0. Jan 10 08:07:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:07:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 12. Jan 10 08:07:00 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:07:00 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:07:03 hn-dlp platform-python[2831]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:07:03 hn-dlp platform-python[2831]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:07:03 hn-dlp platform-python[2831]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:07:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2831]: new replica keys in LDAP: set() Jan 10 08:07:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2831]: obsolete replica keys in local HSM: set() Jan 10 08:07:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2831]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:07:03 hn-dlp ipa-ods-exporter[2831]: Traceback (most recent call last): Jan 10 08:07:03 hn-dlp ipa-ods-exporter[2831]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:07:03 hn-dlp ipa-ods-exporter[2831]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:07:03 hn-dlp ipa-ods-exporter[2831]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:07:03 hn-dlp ipa-ods-exporter[2831]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:07:03 hn-dlp ipa-ods-exporter[2831]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:07:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:07:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:07:12 hn-dlp named-pkcs11[1520]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:07:12 hn-dlp named-pkcs11[1520]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:07:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:07:56 hn-dlp systemd[1]: Starting Cleanup of Temporary Directories... Jan 10 08:07:56 hn-dlp systemd-tmpfiles[2839]: [/etc/tmpfiles.d/dirsrv-IPA-TECIN-NET.conf:1] Line references path below legacy directory /var/run/, updating /var/run/dirsrv → /run/dirsrv; please update the tmpfiles.d/ drop-in file accordingly. Jan 10 08:07:56 hn-dlp systemd-tmpfiles[2839]: [/usr/lib/tmpfiles.d/krb5-krb5kdc.conf:1] Line references path below legacy directory /var/run/, updating /var/run/krb5kdc → /run/krb5kdc; please update the tmpfiles.d/ drop-in file accordingly. Jan 10 08:07:56 hn-dlp systemd[1]: systemd-tmpfiles-clean.service: Succeeded. Jan 10 08:07:56 hn-dlp systemd[1]: Started Cleanup of Temporary Directories. Jan 10 08:08:04 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:08:04 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 13. Jan 10 08:08:04 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:08:04 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:08:06 hn-dlp platform-python[2842]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:08:06 hn-dlp platform-python[2842]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:08:06 hn-dlp platform-python[2842]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:08:07 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2842]: new replica keys in LDAP: set() Jan 10 08:08:07 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2842]: obsolete replica keys in local HSM: set() Jan 10 08:08:07 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2842]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:08:07 hn-dlp ipa-ods-exporter[2842]: Traceback (most recent call last): Jan 10 08:08:07 hn-dlp ipa-ods-exporter[2842]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:08:07 hn-dlp ipa-ods-exporter[2842]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:08:07 hn-dlp ipa-ods-exporter[2842]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:08:07 hn-dlp ipa-ods-exporter[2842]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:08:07 hn-dlp ipa-ods-exporter[2842]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:08:07 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:08:07 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:09:07 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:09:07 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 14. Jan 10 08:09:07 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:09:07 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:09:10 hn-dlp platform-python[2852]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:09:10 hn-dlp platform-python[2852]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:09:10 hn-dlp platform-python[2852]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:09:10 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2852]: new replica keys in LDAP: set() Jan 10 08:09:10 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2852]: obsolete replica keys in local HSM: set() Jan 10 08:09:10 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2852]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 08:09:10 hn-dlp ipa-ods-exporter[2852]: Traceback (most recent call last): Jan 10 08:09:10 hn-dlp ipa-ods-exporter[2852]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:09:10 hn-dlp ipa-ods-exporter[2852]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:09:10 hn-dlp ipa-ods-exporter[2852]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:09:10 hn-dlp ipa-ods-exporter[2852]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:09:10 hn-dlp ipa-ods-exporter[2852]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:09:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:09:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:09:12 hn-dlp named-pkcs11[1520]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:09:12 hn-dlp named-pkcs11[1520]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:09:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:10:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:10:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 15. Jan 10 08:10:10 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:10:10 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:10:13 hn-dlp platform-python[2864]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:10:13 hn-dlp platform-python[2864]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:10:13 hn-dlp platform-python[2864]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:10:13 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2864]: new replica keys in LDAP: set() Jan 10 08:10:13 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2864]: obsolete replica keys in local HSM: set() Jan 10 08:10:13 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2864]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:10:13 hn-dlp ipa-ods-exporter[2864]: Traceback (most recent call last): Jan 10 08:10:13 hn-dlp ipa-ods-exporter[2864]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:10:13 hn-dlp ipa-ods-exporter[2864]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:10:13 hn-dlp ipa-ods-exporter[2864]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:10:13 hn-dlp ipa-ods-exporter[2864]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:10:13 hn-dlp ipa-ods-exporter[2864]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:10:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:10:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:11:12 hn-dlp named-pkcs11[1520]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:11:12 hn-dlp named-pkcs11[1520]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:11:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:11:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 16. Jan 10 08:11:14 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:11:14 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:11:16 hn-dlp platform-python[2873]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:11:16 hn-dlp platform-python[2873]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:11:16 hn-dlp platform-python[2873]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:11:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2873]: new replica keys in LDAP: set() Jan 10 08:11:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2873]: obsolete replica keys in local HSM: set() Jan 10 08:11:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2873]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:11:16 hn-dlp ipa-ods-exporter[2873]: Traceback (most recent call last): Jan 10 08:11:16 hn-dlp ipa-ods-exporter[2873]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:11:16 hn-dlp ipa-ods-exporter[2873]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:11:16 hn-dlp ipa-ods-exporter[2873]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:11:16 hn-dlp ipa-ods-exporter[2873]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:11:16 hn-dlp ipa-ods-exporter[2873]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:11:17 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:11:17 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:11:26 hn-dlp named-pkcs11[1520]: validating 1.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:11:26 hn-dlp named-pkcs11[1520]: broken trust chain resolving '1.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:11:29 hn-dlp named-pkcs11[1520]: validating 2.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:11:29 hn-dlp named-pkcs11[1520]: broken trust chain resolving '2.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:11:31 hn-dlp named-pkcs11[1520]: validating 3.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:11:31 hn-dlp named-pkcs11[1520]: broken trust chain resolving '3.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:11:34 hn-dlp named-pkcs11[1520]: validating 4.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:11:34 hn-dlp named-pkcs11[1520]: broken trust chain resolving '4.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:11:36 hn-dlp named-pkcs11[1520]: validating 5.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:11:36 hn-dlp named-pkcs11[1520]: broken trust chain resolving '5.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:11:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:11:39 hn-dlp named-pkcs11[1520]: validating 6.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:11:39 hn-dlp named-pkcs11[1520]: broken trust chain resolving '6.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:11:42 hn-dlp named-pkcs11[1520]: validating 7.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:11:42 hn-dlp named-pkcs11[1520]: broken trust chain resolving '7.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:11:44 hn-dlp named-pkcs11[1520]: validating 8.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:11:44 hn-dlp named-pkcs11[1520]: broken trust chain resolving '8.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:11:47 hn-dlp named-pkcs11[1520]: validating 9.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:11:47 hn-dlp named-pkcs11[1520]: broken trust chain resolving '9.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:11:49 hn-dlp named-pkcs11[1520]: validating 10.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:11:49 hn-dlp named-pkcs11[1520]: broken trust chain resolving '10.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:11:52 hn-dlp named-pkcs11[1520]: validating 11.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:11:52 hn-dlp named-pkcs11[1520]: broken trust chain resolving '11.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:11:55 hn-dlp named-pkcs11[1520]: validating 12.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:11:55 hn-dlp named-pkcs11[1520]: broken trust chain resolving '12.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:11:57 hn-dlp named-pkcs11[1520]: validating 13.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:11:57 hn-dlp named-pkcs11[1520]: broken trust chain resolving '13.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:00 hn-dlp named-pkcs11[1520]: validating 14.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:00 hn-dlp named-pkcs11[1520]: broken trust chain resolving '14.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:02 hn-dlp named-pkcs11[1520]: validating 15.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:02 hn-dlp named-pkcs11[1520]: broken trust chain resolving '15.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:05 hn-dlp named-pkcs11[1520]: validating 16.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:05 hn-dlp named-pkcs11[1520]: broken trust chain resolving '16.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:08 hn-dlp named-pkcs11[1520]: validating 17.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:08 hn-dlp named-pkcs11[1520]: broken trust chain resolving '17.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:10 hn-dlp named-pkcs11[1520]: validating 18.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:10 hn-dlp named-pkcs11[1520]: broken trust chain resolving '18.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:13 hn-dlp named-pkcs11[1520]: validating 19.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:13 hn-dlp named-pkcs11[1520]: broken trust chain resolving '19.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:16 hn-dlp named-pkcs11[1520]: validating 20.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:16 hn-dlp named-pkcs11[1520]: broken trust chain resolving '20.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:17 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:12:17 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 17. Jan 10 08:12:17 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:12:17 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:12:18 hn-dlp named-pkcs11[1520]: validating 21.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:18 hn-dlp named-pkcs11[1520]: broken trust chain resolving '21.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:19 hn-dlp platform-python[2881]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:12:19 hn-dlp platform-python[2881]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:12:19 hn-dlp platform-python[2881]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:12:20 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2881]: new replica keys in LDAP: set() Jan 10 08:12:20 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2881]: obsolete replica keys in local HSM: set() Jan 10 08:12:20 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2881]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 08:12:20 hn-dlp ipa-ods-exporter[2881]: Traceback (most recent call last): Jan 10 08:12:20 hn-dlp ipa-ods-exporter[2881]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:12:20 hn-dlp ipa-ods-exporter[2881]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:12:20 hn-dlp ipa-ods-exporter[2881]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:12:20 hn-dlp ipa-ods-exporter[2881]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:12:20 hn-dlp ipa-ods-exporter[2881]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:12:20 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:12:20 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:12:21 hn-dlp named-pkcs11[1520]: validating 22.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:21 hn-dlp named-pkcs11[1520]: broken trust chain resolving '22.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:23 hn-dlp named-pkcs11[1520]: validating 23.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:23 hn-dlp named-pkcs11[1520]: broken trust chain resolving '23.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:26 hn-dlp named-pkcs11[1520]: validating 24.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:26 hn-dlp named-pkcs11[1520]: broken trust chain resolving '24.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:28 hn-dlp named-pkcs11[1520]: validating 25.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:28 hn-dlp named-pkcs11[1520]: broken trust chain resolving '25.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:31 hn-dlp named-pkcs11[1520]: validating 26.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:31 hn-dlp named-pkcs11[1520]: broken trust chain resolving '26.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:34 hn-dlp named-pkcs11[1520]: validating 27.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:34 hn-dlp named-pkcs11[1520]: broken trust chain resolving '27.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:36 hn-dlp named-pkcs11[1520]: validating 28.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:36 hn-dlp named-pkcs11[1520]: broken trust chain resolving '28.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:39 hn-dlp named-pkcs11[1520]: validating 29.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:39 hn-dlp named-pkcs11[1520]: broken trust chain resolving '29.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:42 hn-dlp named-pkcs11[1520]: validating 30.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:42 hn-dlp named-pkcs11[1520]: broken trust chain resolving '30.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:44 hn-dlp named-pkcs11[1520]: validating 31.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:44 hn-dlp named-pkcs11[1520]: broken trust chain resolving '31.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:47 hn-dlp named-pkcs11[1520]: validating 32.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:47 hn-dlp named-pkcs11[1520]: broken trust chain resolving '32.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:49 hn-dlp named-pkcs11[1520]: validating 33.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:49 hn-dlp named-pkcs11[1520]: broken trust chain resolving '33.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:52 hn-dlp named-pkcs11[1520]: validating 34.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:52 hn-dlp named-pkcs11[1520]: broken trust chain resolving '34.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:55 hn-dlp named-pkcs11[1520]: validating 35.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:55 hn-dlp named-pkcs11[1520]: broken trust chain resolving '35.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:12:57 hn-dlp named-pkcs11[1520]: validating 36.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:12:57 hn-dlp named-pkcs11[1520]: broken trust chain resolving '36.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:00 hn-dlp named-pkcs11[1520]: validating 37.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:00 hn-dlp named-pkcs11[1520]: broken trust chain resolving '37.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:02 hn-dlp named-pkcs11[1520]: validating 38.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:02 hn-dlp named-pkcs11[1520]: broken trust chain resolving '38.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:05 hn-dlp named-pkcs11[1520]: validating 39.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:05 hn-dlp named-pkcs11[1520]: broken trust chain resolving '39.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:08 hn-dlp named-pkcs11[1520]: validating 40.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:08 hn-dlp named-pkcs11[1520]: broken trust chain resolving '40.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:10 hn-dlp named-pkcs11[1520]: validating 41.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:10 hn-dlp named-pkcs11[1520]: broken trust chain resolving '41.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:12 hn-dlp named-pkcs11[1520]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:12 hn-dlp named-pkcs11[1520]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:13 hn-dlp named-pkcs11[1520]: validating 42.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:13 hn-dlp named-pkcs11[1520]: broken trust chain resolving '42.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:15 hn-dlp named-pkcs11[1520]: validating 43.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:15 hn-dlp named-pkcs11[1520]: broken trust chain resolving '43.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:18 hn-dlp named-pkcs11[1520]: validating 44.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:18 hn-dlp named-pkcs11[1520]: broken trust chain resolving '44.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:20 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:13:20 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 18. Jan 10 08:13:20 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:13:20 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:13:21 hn-dlp named-pkcs11[1520]: validating 45.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:21 hn-dlp named-pkcs11[1520]: broken trust chain resolving '45.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:23 hn-dlp platform-python[2891]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:13:23 hn-dlp platform-python[2891]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:13:23 hn-dlp platform-python[2891]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:13:23 hn-dlp named-pkcs11[1520]: validating 46.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:23 hn-dlp named-pkcs11[1520]: broken trust chain resolving '46.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2891]: new replica keys in LDAP: set() Jan 10 08:13:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2891]: obsolete replica keys in local HSM: set() Jan 10 08:13:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2891]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 08:13:23 hn-dlp ipa-ods-exporter[2891]: Traceback (most recent call last): Jan 10 08:13:23 hn-dlp ipa-ods-exporter[2891]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:13:23 hn-dlp ipa-ods-exporter[2891]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:13:23 hn-dlp ipa-ods-exporter[2891]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:13:23 hn-dlp ipa-ods-exporter[2891]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:13:23 hn-dlp ipa-ods-exporter[2891]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:13:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:13:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:13:26 hn-dlp named-pkcs11[1520]: validating 47.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:26 hn-dlp named-pkcs11[1520]: broken trust chain resolving '47.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:28 hn-dlp named-pkcs11[1520]: validating 48.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:28 hn-dlp named-pkcs11[1520]: broken trust chain resolving '48.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:31 hn-dlp named-pkcs11[1520]: validating 49.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:31 hn-dlp named-pkcs11[1520]: broken trust chain resolving '49.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:33 hn-dlp named-pkcs11[1520]: validating 50.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:33 hn-dlp named-pkcs11[1520]: broken trust chain resolving '50.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:36 hn-dlp named-pkcs11[1520]: validating 51.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:36 hn-dlp named-pkcs11[1520]: broken trust chain resolving '51.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:13:39 hn-dlp named-pkcs11[1520]: validating 52.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:39 hn-dlp named-pkcs11[1520]: broken trust chain resolving '52.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:41 hn-dlp named-pkcs11[1520]: validating 53.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:41 hn-dlp named-pkcs11[1520]: broken trust chain resolving '53.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:44 hn-dlp named-pkcs11[1520]: validating 54.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:44 hn-dlp named-pkcs11[1520]: broken trust chain resolving '54.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:46 hn-dlp named-pkcs11[1520]: validating 55.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:46 hn-dlp named-pkcs11[1520]: broken trust chain resolving '55.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:49 hn-dlp named-pkcs11[1520]: validating 56.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:49 hn-dlp named-pkcs11[1520]: broken trust chain resolving '56.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:52 hn-dlp named-pkcs11[1520]: validating 57.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:52 hn-dlp named-pkcs11[1520]: broken trust chain resolving '57.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:54 hn-dlp named-pkcs11[1520]: validating 58.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:54 hn-dlp named-pkcs11[1520]: broken trust chain resolving '58.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:57 hn-dlp named-pkcs11[1520]: validating 59.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:57 hn-dlp named-pkcs11[1520]: broken trust chain resolving '59.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:13:59 hn-dlp named-pkcs11[1520]: validating 60.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:13:59 hn-dlp named-pkcs11[1520]: broken trust chain resolving '60.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:02 hn-dlp named-pkcs11[1520]: validating 61.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:02 hn-dlp named-pkcs11[1520]: broken trust chain resolving '61.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:05 hn-dlp named-pkcs11[1520]: validating 62.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:05 hn-dlp named-pkcs11[1520]: broken trust chain resolving '62.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:07 hn-dlp named-pkcs11[1520]: validating 63.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:07 hn-dlp named-pkcs11[1520]: broken trust chain resolving '63.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:10 hn-dlp named-pkcs11[1520]: validating 64.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:10 hn-dlp named-pkcs11[1520]: broken trust chain resolving '64.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:12 hn-dlp named-pkcs11[1520]: validating 65.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:12 hn-dlp named-pkcs11[1520]: broken trust chain resolving '65.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:15 hn-dlp named-pkcs11[1520]: validating 66.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:15 hn-dlp named-pkcs11[1520]: broken trust chain resolving '66.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:18 hn-dlp named-pkcs11[1520]: validating 67.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:18 hn-dlp named-pkcs11[1520]: broken trust chain resolving '67.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:20 hn-dlp named-pkcs11[1520]: validating 68.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:20 hn-dlp named-pkcs11[1520]: broken trust chain resolving '68.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:23 hn-dlp named-pkcs11[1520]: validating 69.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:23 hn-dlp named-pkcs11[1520]: broken trust chain resolving '69.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:14:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 19. Jan 10 08:14:24 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:14:24 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:14:25 hn-dlp named-pkcs11[1520]: validating 70.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:25 hn-dlp named-pkcs11[1520]: broken trust chain resolving '70.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:26 hn-dlp platform-python[2901]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:14:26 hn-dlp platform-python[2901]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:14:26 hn-dlp platform-python[2901]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:14:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2901]: new replica keys in LDAP: set() Jan 10 08:14:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2901]: obsolete replica keys in local HSM: set() Jan 10 08:14:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2901]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 08:14:27 hn-dlp ipa-ods-exporter[2901]: Traceback (most recent call last): Jan 10 08:14:27 hn-dlp ipa-ods-exporter[2901]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:14:27 hn-dlp ipa-ods-exporter[2901]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:14:27 hn-dlp ipa-ods-exporter[2901]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:14:27 hn-dlp ipa-ods-exporter[2901]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:14:27 hn-dlp ipa-ods-exporter[2901]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:14:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:14:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:14:28 hn-dlp named-pkcs11[1520]: validating 71.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:28 hn-dlp named-pkcs11[1520]: broken trust chain resolving '71.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:31 hn-dlp named-pkcs11[1520]: validating 72.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:31 hn-dlp named-pkcs11[1520]: broken trust chain resolving '72.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:33 hn-dlp named-pkcs11[1520]: validating 73.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:33 hn-dlp named-pkcs11[1520]: broken trust chain resolving '73.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:36 hn-dlp named-pkcs11[1520]: validating 74.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:36 hn-dlp named-pkcs11[1520]: broken trust chain resolving '74.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:38 hn-dlp named-pkcs11[1520]: validating 75.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:38 hn-dlp named-pkcs11[1520]: broken trust chain resolving '75.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:41 hn-dlp named-pkcs11[1520]: validating 76.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:41 hn-dlp named-pkcs11[1520]: broken trust chain resolving '76.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:44 hn-dlp named-pkcs11[1520]: validating 77.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:44 hn-dlp named-pkcs11[1520]: broken trust chain resolving '77.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:46 hn-dlp named-pkcs11[1520]: validating 78.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:46 hn-dlp named-pkcs11[1520]: broken trust chain resolving '78.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:49 hn-dlp named-pkcs11[1520]: validating 79.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:49 hn-dlp named-pkcs11[1520]: broken trust chain resolving '79.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:51 hn-dlp named-pkcs11[1520]: validating 80.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:51 hn-dlp named-pkcs11[1520]: broken trust chain resolving '80.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:54 hn-dlp named-pkcs11[1520]: validating 81.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:54 hn-dlp named-pkcs11[1520]: broken trust chain resolving '81.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:57 hn-dlp named-pkcs11[1520]: validating 82.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:57 hn-dlp named-pkcs11[1520]: broken trust chain resolving '82.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:14:59 hn-dlp named-pkcs11[1520]: validating 83.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:14:59 hn-dlp named-pkcs11[1520]: broken trust chain resolving '83.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:02 hn-dlp named-pkcs11[1520]: validating 84.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:02 hn-dlp named-pkcs11[1520]: broken trust chain resolving '84.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:04 hn-dlp named-pkcs11[1520]: validating 85.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:04 hn-dlp named-pkcs11[1520]: broken trust chain resolving '85.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:07 hn-dlp named-pkcs11[1520]: validating 86.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:07 hn-dlp named-pkcs11[1520]: broken trust chain resolving '86.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:09 hn-dlp named-pkcs11[1520]: validating 87.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:09 hn-dlp named-pkcs11[1520]: broken trust chain resolving '87.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:12 hn-dlp named-pkcs11[1520]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 08:15:12 hn-dlp named-pkcs11[1520]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:12 hn-dlp named-pkcs11[1520]: validating 88.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:12 hn-dlp named-pkcs11[1520]: broken trust chain resolving '88.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:15 hn-dlp named-pkcs11[1520]: validating 89.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:15 hn-dlp named-pkcs11[1520]: broken trust chain resolving '89.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:17 hn-dlp named-pkcs11[1520]: validating 90.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:17 hn-dlp named-pkcs11[1520]: broken trust chain resolving '90.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:20 hn-dlp named-pkcs11[1520]: validating 91.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:20 hn-dlp named-pkcs11[1520]: broken trust chain resolving '91.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:22 hn-dlp named-pkcs11[1520]: validating 92.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:22 hn-dlp named-pkcs11[1520]: broken trust chain resolving '92.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:25 hn-dlp named-pkcs11[1520]: validating 93.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:25 hn-dlp named-pkcs11[1520]: broken trust chain resolving '93.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:15:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 20. Jan 10 08:15:27 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:15:27 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:15:28 hn-dlp named-pkcs11[1520]: validating 94.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:28 hn-dlp named-pkcs11[1520]: broken trust chain resolving '94.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:30 hn-dlp platform-python[2911]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:15:30 hn-dlp platform-python[2911]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:15:30 hn-dlp platform-python[2911]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:15:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2911]: new replica keys in LDAP: set() Jan 10 08:15:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2911]: obsolete replica keys in local HSM: set() Jan 10 08:15:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2911]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 08:15:30 hn-dlp ipa-ods-exporter[2911]: Traceback (most recent call last): Jan 10 08:15:30 hn-dlp ipa-ods-exporter[2911]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:15:30 hn-dlp ipa-ods-exporter[2911]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:15:30 hn-dlp ipa-ods-exporter[2911]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:15:30 hn-dlp ipa-ods-exporter[2911]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:15:30 hn-dlp ipa-ods-exporter[2911]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:15:30 hn-dlp named-pkcs11[1520]: validating 95.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:30 hn-dlp named-pkcs11[1520]: broken trust chain resolving '95.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:15:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:15:33 hn-dlp named-pkcs11[1520]: validating 96.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:33 hn-dlp named-pkcs11[1520]: broken trust chain resolving '96.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:35 hn-dlp named-pkcs11[1520]: validating 97.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:35 hn-dlp named-pkcs11[1520]: broken trust chain resolving '97.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:15:38 hn-dlp named-pkcs11[1520]: validating 98.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:38 hn-dlp named-pkcs11[1520]: broken trust chain resolving '98.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:41 hn-dlp named-pkcs11[1520]: validating 99.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:41 hn-dlp named-pkcs11[1520]: broken trust chain resolving '99.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:43 hn-dlp named-pkcs11[1520]: validating 100.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:43 hn-dlp named-pkcs11[1520]: broken trust chain resolving '100.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:45 hn-dlp named-pkcs11[1520]: validating 101.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:45 hn-dlp named-pkcs11[1520]: broken trust chain resolving '101.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:47 hn-dlp named-pkcs11[1520]: validating 102.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:47 hn-dlp named-pkcs11[1520]: broken trust chain resolving '102.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:50 hn-dlp named-pkcs11[1520]: validating 103.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:50 hn-dlp named-pkcs11[1520]: broken trust chain resolving '103.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:52 hn-dlp named-pkcs11[1520]: validating 104.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:52 hn-dlp named-pkcs11[1520]: broken trust chain resolving '104.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:54 hn-dlp named-pkcs11[1520]: validating 105.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:54 hn-dlp named-pkcs11[1520]: broken trust chain resolving '105.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:56 hn-dlp named-pkcs11[1520]: validating 106.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:56 hn-dlp named-pkcs11[1520]: broken trust chain resolving '106.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:15:58 hn-dlp named-pkcs11[1520]: validating 107.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:15:58 hn-dlp named-pkcs11[1520]: broken trust chain resolving '107.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:01 hn-dlp named-pkcs11[1520]: validating 108.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:01 hn-dlp named-pkcs11[1520]: broken trust chain resolving '108.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:03 hn-dlp named-pkcs11[1520]: validating 109.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '109.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:05 hn-dlp named-pkcs11[1520]: validating 110.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:05 hn-dlp named-pkcs11[1520]: broken trust chain resolving '110.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:07 hn-dlp named-pkcs11[1520]: validating 111.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:07 hn-dlp named-pkcs11[1520]: broken trust chain resolving '111.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:10 hn-dlp named-pkcs11[1520]: validating 112.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:10 hn-dlp named-pkcs11[1520]: broken trust chain resolving '112.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:13 hn-dlp named-pkcs11[1520]: validating 113.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:13 hn-dlp named-pkcs11[1520]: broken trust chain resolving '113.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:15 hn-dlp named-pkcs11[1520]: validating 114.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:15 hn-dlp named-pkcs11[1520]: broken trust chain resolving '114.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:17 hn-dlp named-pkcs11[1520]: validating 115.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:17 hn-dlp named-pkcs11[1520]: broken trust chain resolving '115.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:19 hn-dlp named-pkcs11[1520]: validating 116.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:19 hn-dlp named-pkcs11[1520]: broken trust chain resolving '116.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:22 hn-dlp named-pkcs11[1520]: validating 117.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:22 hn-dlp named-pkcs11[1520]: broken trust chain resolving '117.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:24 hn-dlp named-pkcs11[1520]: validating 118.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:24 hn-dlp named-pkcs11[1520]: broken trust chain resolving '118.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:27 hn-dlp named-pkcs11[1520]: validating 119.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:27 hn-dlp named-pkcs11[1520]: broken trust chain resolving '119.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:30 hn-dlp named-pkcs11[1520]: validating 120.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:30 hn-dlp named-pkcs11[1520]: broken trust chain resolving '120.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:16:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 21. Jan 10 08:16:31 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:16:31 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:16:32 hn-dlp named-pkcs11[1520]: validating 121.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:32 hn-dlp named-pkcs11[1520]: broken trust chain resolving '121.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:33 hn-dlp platform-python[2919]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:16:33 hn-dlp platform-python[2919]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:16:33 hn-dlp platform-python[2919]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:16:34 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2919]: new replica keys in LDAP: set() Jan 10 08:16:34 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2919]: obsolete replica keys in local HSM: set() Jan 10 08:16:34 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2919]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 08:16:34 hn-dlp ipa-ods-exporter[2919]: Traceback (most recent call last): Jan 10 08:16:34 hn-dlp ipa-ods-exporter[2919]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:16:34 hn-dlp ipa-ods-exporter[2919]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:16:34 hn-dlp ipa-ods-exporter[2919]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:16:34 hn-dlp ipa-ods-exporter[2919]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:16:34 hn-dlp ipa-ods-exporter[2919]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:16:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:16:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:16:35 hn-dlp named-pkcs11[1520]: validating 122.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:35 hn-dlp named-pkcs11[1520]: broken trust chain resolving '122.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:37 hn-dlp named-pkcs11[1520]: validating 123.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:37 hn-dlp named-pkcs11[1520]: broken trust chain resolving '123.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:40 hn-dlp named-pkcs11[1520]: validating 124.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:40 hn-dlp named-pkcs11[1520]: broken trust chain resolving '124.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:43 hn-dlp named-pkcs11[1520]: validating 125.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:43 hn-dlp named-pkcs11[1520]: broken trust chain resolving '125.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:45 hn-dlp named-pkcs11[1520]: validating 126.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:45 hn-dlp named-pkcs11[1520]: broken trust chain resolving '126.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:48 hn-dlp named-pkcs11[1520]: validating 127.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:48 hn-dlp named-pkcs11[1520]: broken trust chain resolving '127.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:50 hn-dlp named-pkcs11[1520]: validating 128.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:50 hn-dlp named-pkcs11[1520]: broken trust chain resolving '128.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:53 hn-dlp named-pkcs11[1520]: validating 129.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:53 hn-dlp named-pkcs11[1520]: broken trust chain resolving '129.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:56 hn-dlp named-pkcs11[1520]: validating 130.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:56 hn-dlp named-pkcs11[1520]: broken trust chain resolving '130.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:16:58 hn-dlp named-pkcs11[1520]: validating 131.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:16:58 hn-dlp named-pkcs11[1520]: broken trust chain resolving '131.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:01 hn-dlp named-pkcs11[1520]: validating 132.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:01 hn-dlp named-pkcs11[1520]: broken trust chain resolving '132.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:03 hn-dlp named-pkcs11[1520]: validating 133.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '133.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:06 hn-dlp named-pkcs11[1520]: validating 134.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:06 hn-dlp named-pkcs11[1520]: broken trust chain resolving '134.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:09 hn-dlp named-pkcs11[1520]: validating 135.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:09 hn-dlp named-pkcs11[1520]: broken trust chain resolving '135.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:11 hn-dlp named-pkcs11[1520]: validating 136.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:11 hn-dlp named-pkcs11[1520]: broken trust chain resolving '136.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:12 hn-dlp named-pkcs11[1520]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:12 hn-dlp named-pkcs11[1520]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:14 hn-dlp named-pkcs11[1520]: validating 137.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:14 hn-dlp named-pkcs11[1520]: broken trust chain resolving '137.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:16 hn-dlp named-pkcs11[1520]: validating 138.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:16 hn-dlp named-pkcs11[1520]: broken trust chain resolving '138.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:19 hn-dlp named-pkcs11[1520]: validating 139.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:19 hn-dlp named-pkcs11[1520]: broken trust chain resolving '139.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:22 hn-dlp named-pkcs11[1520]: validating 140.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:22 hn-dlp named-pkcs11[1520]: broken trust chain resolving '140.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:24 hn-dlp named-pkcs11[1520]: validating 141.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:24 hn-dlp named-pkcs11[1520]: broken trust chain resolving '141.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:27 hn-dlp named-pkcs11[1520]: validating 142.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:27 hn-dlp named-pkcs11[1520]: broken trust chain resolving '142.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:29 hn-dlp named-pkcs11[1520]: validating 143.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:29 hn-dlp named-pkcs11[1520]: broken trust chain resolving '143.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:32 hn-dlp named-pkcs11[1520]: validating 144.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:32 hn-dlp named-pkcs11[1520]: broken trust chain resolving '144.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:17:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 22. Jan 10 08:17:34 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:17:34 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:17:35 hn-dlp named-pkcs11[1520]: validating 145.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:35 hn-dlp named-pkcs11[1520]: broken trust chain resolving '145.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:36 hn-dlp platform-python[2928]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:17:36 hn-dlp platform-python[2928]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:17:36 hn-dlp platform-python[2928]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:17:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2928]: new replica keys in LDAP: set() Jan 10 08:17:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2928]: obsolete replica keys in local HSM: set() Jan 10 08:17:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2928]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:17:37 hn-dlp ipa-ods-exporter[2928]: Traceback (most recent call last): Jan 10 08:17:37 hn-dlp ipa-ods-exporter[2928]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:17:37 hn-dlp ipa-ods-exporter[2928]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:17:37 hn-dlp ipa-ods-exporter[2928]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:17:37 hn-dlp ipa-ods-exporter[2928]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:17:37 hn-dlp ipa-ods-exporter[2928]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:17:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:17:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:17:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:17:37 hn-dlp named-pkcs11[1520]: validating 146.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:37 hn-dlp named-pkcs11[1520]: broken trust chain resolving '146.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:40 hn-dlp named-pkcs11[1520]: validating 147.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:40 hn-dlp named-pkcs11[1520]: broken trust chain resolving '147.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:42 hn-dlp named-pkcs11[1520]: validating 148.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:42 hn-dlp named-pkcs11[1520]: broken trust chain resolving '148.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:45 hn-dlp named-pkcs11[1520]: validating 149.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:45 hn-dlp named-pkcs11[1520]: broken trust chain resolving '149.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:48 hn-dlp named-pkcs11[1520]: validating 150.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:48 hn-dlp named-pkcs11[1520]: broken trust chain resolving '150.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:50 hn-dlp named-pkcs11[1520]: validating 151.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:50 hn-dlp named-pkcs11[1520]: broken trust chain resolving '151.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:53 hn-dlp named-pkcs11[1520]: validating 152.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:53 hn-dlp named-pkcs11[1520]: broken trust chain resolving '152.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:56 hn-dlp named-pkcs11[1520]: validating 153.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:56 hn-dlp named-pkcs11[1520]: broken trust chain resolving '153.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:17:58 hn-dlp named-pkcs11[1520]: validating 154.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:17:58 hn-dlp named-pkcs11[1520]: broken trust chain resolving '154.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:01 hn-dlp named-pkcs11[1520]: validating 155.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:01 hn-dlp named-pkcs11[1520]: broken trust chain resolving '155.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:03 hn-dlp named-pkcs11[1520]: validating 156.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '156.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:06 hn-dlp named-pkcs11[1520]: validating 157.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:06 hn-dlp named-pkcs11[1520]: broken trust chain resolving '157.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:09 hn-dlp named-pkcs11[1520]: validating 158.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:09 hn-dlp named-pkcs11[1520]: broken trust chain resolving '158.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:11 hn-dlp named-pkcs11[1520]: validating 159.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:11 hn-dlp named-pkcs11[1520]: broken trust chain resolving '159.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:14 hn-dlp named-pkcs11[1520]: validating 160.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:14 hn-dlp named-pkcs11[1520]: broken trust chain resolving '160.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:16 hn-dlp named-pkcs11[1520]: validating 161.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:16 hn-dlp named-pkcs11[1520]: broken trust chain resolving '161.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:19 hn-dlp named-pkcs11[1520]: validating 162.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:19 hn-dlp named-pkcs11[1520]: broken trust chain resolving '162.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:21 hn-dlp named-pkcs11[1520]: validating 163.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:21 hn-dlp named-pkcs11[1520]: broken trust chain resolving '163.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:24 hn-dlp named-pkcs11[1520]: validating 164.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:24 hn-dlp named-pkcs11[1520]: broken trust chain resolving '164.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:27 hn-dlp named-pkcs11[1520]: validating 165.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:27 hn-dlp named-pkcs11[1520]: broken trust chain resolving '165.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:29 hn-dlp named-pkcs11[1520]: validating 166.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:29 hn-dlp named-pkcs11[1520]: broken trust chain resolving '166.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:32 hn-dlp named-pkcs11[1520]: validating 167.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:32 hn-dlp named-pkcs11[1520]: broken trust chain resolving '167.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:34 hn-dlp named-pkcs11[1520]: validating 168.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:34 hn-dlp named-pkcs11[1520]: broken trust chain resolving '168.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:18:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 23. Jan 10 08:18:37 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:18:37 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:18:37 hn-dlp named-pkcs11[1520]: validating 169.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:37 hn-dlp named-pkcs11[1520]: broken trust chain resolving '169.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:39 hn-dlp platform-python[2937]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:18:39 hn-dlp platform-python[2937]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:18:39 hn-dlp platform-python[2937]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:18:40 hn-dlp named-pkcs11[1520]: validating 170.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:40 hn-dlp named-pkcs11[1520]: broken trust chain resolving '170.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2937]: new replica keys in LDAP: set() Jan 10 08:18:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2937]: obsolete replica keys in local HSM: set() Jan 10 08:18:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2937]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:18:40 hn-dlp ipa-ods-exporter[2937]: Traceback (most recent call last): Jan 10 08:18:40 hn-dlp ipa-ods-exporter[2937]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:18:40 hn-dlp ipa-ods-exporter[2937]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:18:40 hn-dlp ipa-ods-exporter[2937]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:18:40 hn-dlp ipa-ods-exporter[2937]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:18:40 hn-dlp ipa-ods-exporter[2937]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:18:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:18:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:18:42 hn-dlp named-pkcs11[1520]: validating 171.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:42 hn-dlp named-pkcs11[1520]: broken trust chain resolving '171.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:45 hn-dlp named-pkcs11[1520]: validating 172.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:45 hn-dlp named-pkcs11[1520]: broken trust chain resolving '172.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:47 hn-dlp named-pkcs11[1520]: validating 173.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:47 hn-dlp named-pkcs11[1520]: broken trust chain resolving '173.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:50 hn-dlp named-pkcs11[1520]: validating 174.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:50 hn-dlp named-pkcs11[1520]: broken trust chain resolving '174.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:52 hn-dlp named-pkcs11[1520]: validating 175.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:52 hn-dlp named-pkcs11[1520]: broken trust chain resolving '175.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:55 hn-dlp named-pkcs11[1520]: validating 176.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:55 hn-dlp named-pkcs11[1520]: broken trust chain resolving '176.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:18:58 hn-dlp named-pkcs11[1520]: validating 177.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:18:58 hn-dlp named-pkcs11[1520]: broken trust chain resolving '177.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:00 hn-dlp named-pkcs11[1520]: validating 178.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:00 hn-dlp named-pkcs11[1520]: broken trust chain resolving '178.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:03 hn-dlp named-pkcs11[1520]: validating 179.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '179.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:05 hn-dlp named-pkcs11[1520]: validating 180.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:05 hn-dlp named-pkcs11[1520]: broken trust chain resolving '180.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:08 hn-dlp named-pkcs11[1520]: validating 181.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:08 hn-dlp named-pkcs11[1520]: broken trust chain resolving '181.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:11 hn-dlp named-pkcs11[1520]: validating 182.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:11 hn-dlp named-pkcs11[1520]: broken trust chain resolving '182.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:12 hn-dlp named-pkcs11[1520]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:12 hn-dlp named-pkcs11[1520]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:13 hn-dlp named-pkcs11[1520]: validating 183.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:13 hn-dlp named-pkcs11[1520]: broken trust chain resolving '183.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:16 hn-dlp named-pkcs11[1520]: validating 184.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:16 hn-dlp named-pkcs11[1520]: broken trust chain resolving '184.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:18 hn-dlp named-pkcs11[1520]: validating 185.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:18 hn-dlp named-pkcs11[1520]: broken trust chain resolving '185.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:21 hn-dlp named-pkcs11[1520]: validating 186.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:21 hn-dlp named-pkcs11[1520]: broken trust chain resolving '186.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:24 hn-dlp named-pkcs11[1520]: validating 187.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:24 hn-dlp named-pkcs11[1520]: broken trust chain resolving '187.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:26 hn-dlp named-pkcs11[1520]: validating 188.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:26 hn-dlp named-pkcs11[1520]: broken trust chain resolving '188.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:29 hn-dlp named-pkcs11[1520]: validating 189.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:29 hn-dlp named-pkcs11[1520]: broken trust chain resolving '189.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:31 hn-dlp named-pkcs11[1520]: validating 190.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:31 hn-dlp named-pkcs11[1520]: broken trust chain resolving '190.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:34 hn-dlp named-pkcs11[1520]: validating 191.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:34 hn-dlp named-pkcs11[1520]: broken trust chain resolving '191.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:37 hn-dlp named-pkcs11[1520]: validating 192.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:37 hn-dlp named-pkcs11[1520]: broken trust chain resolving '192.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:19:39 hn-dlp named-pkcs11[1520]: validating 193.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:39 hn-dlp named-pkcs11[1520]: broken trust chain resolving '193.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:19:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 24. Jan 10 08:19:40 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:19:40 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:19:41 hn-dlp named-pkcs11[1520]: validating 194.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:41 hn-dlp named-pkcs11[1520]: broken trust chain resolving '194.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:43 hn-dlp platform-python[2947]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:19:43 hn-dlp platform-python[2947]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:19:43 hn-dlp platform-python[2947]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:19:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2947]: new replica keys in LDAP: set() Jan 10 08:19:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2947]: obsolete replica keys in local HSM: set() Jan 10 08:19:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2947]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:19:43 hn-dlp ipa-ods-exporter[2947]: Traceback (most recent call last): Jan 10 08:19:43 hn-dlp ipa-ods-exporter[2947]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:19:43 hn-dlp ipa-ods-exporter[2947]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:19:43 hn-dlp ipa-ods-exporter[2947]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:19:43 hn-dlp ipa-ods-exporter[2947]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:19:43 hn-dlp ipa-ods-exporter[2947]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:19:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:19:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:19:43 hn-dlp named-pkcs11[1520]: validating 195.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:43 hn-dlp named-pkcs11[1520]: broken trust chain resolving '195.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:46 hn-dlp named-pkcs11[1520]: validating 196.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:46 hn-dlp named-pkcs11[1520]: broken trust chain resolving '196.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:49 hn-dlp named-pkcs11[1520]: validating 197.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:49 hn-dlp named-pkcs11[1520]: broken trust chain resolving '197.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:51 hn-dlp named-pkcs11[1520]: validating 198.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:51 hn-dlp named-pkcs11[1520]: broken trust chain resolving '198.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:54 hn-dlp named-pkcs11[1520]: validating 199.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:54 hn-dlp named-pkcs11[1520]: broken trust chain resolving '199.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:56 hn-dlp named-pkcs11[1520]: validating 200.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:56 hn-dlp named-pkcs11[1520]: broken trust chain resolving '200.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:19:59 hn-dlp named-pkcs11[1520]: validating 201.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:19:59 hn-dlp named-pkcs11[1520]: broken trust chain resolving '201.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:01 hn-dlp named-pkcs11[1520]: validating 202.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:01 hn-dlp named-pkcs11[1520]: broken trust chain resolving '202.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:04 hn-dlp named-pkcs11[1520]: validating 203.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:04 hn-dlp named-pkcs11[1520]: broken trust chain resolving '203.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:06 hn-dlp named-pkcs11[1520]: validating 204.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:06 hn-dlp named-pkcs11[1520]: broken trust chain resolving '204.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:09 hn-dlp named-pkcs11[1520]: validating 205.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:09 hn-dlp named-pkcs11[1520]: broken trust chain resolving '205.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:11 hn-dlp named-pkcs11[1520]: validating 206.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:11 hn-dlp named-pkcs11[1520]: broken trust chain resolving '206.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:14 hn-dlp named-pkcs11[1520]: validating 207.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:14 hn-dlp named-pkcs11[1520]: broken trust chain resolving '207.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:17 hn-dlp named-pkcs11[1520]: validating 208.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:17 hn-dlp named-pkcs11[1520]: broken trust chain resolving '208.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:19 hn-dlp named-pkcs11[1520]: validating 209.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:19 hn-dlp named-pkcs11[1520]: broken trust chain resolving '209.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:22 hn-dlp named-pkcs11[1520]: validating 210.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:22 hn-dlp named-pkcs11[1520]: broken trust chain resolving '210.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:24 hn-dlp named-pkcs11[1520]: validating 211.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:24 hn-dlp named-pkcs11[1520]: broken trust chain resolving '211.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:27 hn-dlp named-pkcs11[1520]: validating 212.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:27 hn-dlp named-pkcs11[1520]: broken trust chain resolving '212.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:29 hn-dlp named-pkcs11[1520]: validating 213.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:29 hn-dlp named-pkcs11[1520]: broken trust chain resolving '213.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:32 hn-dlp named-pkcs11[1520]: validating 214.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:32 hn-dlp named-pkcs11[1520]: broken trust chain resolving '214.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:35 hn-dlp named-pkcs11[1520]: validating 215.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:35 hn-dlp named-pkcs11[1520]: broken trust chain resolving '215.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:37 hn-dlp named-pkcs11[1520]: validating 216.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:37 hn-dlp named-pkcs11[1520]: broken trust chain resolving '216.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:40 hn-dlp named-pkcs11[1520]: validating 217.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:40 hn-dlp named-pkcs11[1520]: broken trust chain resolving '217.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:42 hn-dlp named-pkcs11[1520]: validating 218.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:42 hn-dlp named-pkcs11[1520]: broken trust chain resolving '218.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:20:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 25. Jan 10 08:20:43 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:20:43 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:20:45 hn-dlp named-pkcs11[1520]: validating 219.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:45 hn-dlp named-pkcs11[1520]: broken trust chain resolving '219.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:46 hn-dlp platform-python[2961]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:20:46 hn-dlp platform-python[2961]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:20:46 hn-dlp platform-python[2961]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:20:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2961]: new replica keys in LDAP: set() Jan 10 08:20:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2961]: obsolete replica keys in local HSM: set() Jan 10 08:20:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2961]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:20:46 hn-dlp ipa-ods-exporter[2961]: Traceback (most recent call last): Jan 10 08:20:46 hn-dlp ipa-ods-exporter[2961]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:20:46 hn-dlp ipa-ods-exporter[2961]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:20:46 hn-dlp ipa-ods-exporter[2961]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:20:46 hn-dlp ipa-ods-exporter[2961]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:20:46 hn-dlp ipa-ods-exporter[2961]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:20:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:20:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:20:48 hn-dlp named-pkcs11[1520]: validating 220.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:48 hn-dlp named-pkcs11[1520]: broken trust chain resolving '220.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:50 hn-dlp named-pkcs11[1520]: validating 221.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:50 hn-dlp named-pkcs11[1520]: broken trust chain resolving '221.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:53 hn-dlp named-pkcs11[1520]: validating 222.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:53 hn-dlp named-pkcs11[1520]: broken trust chain resolving '222.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:55 hn-dlp named-pkcs11[1520]: validating 223.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:55 hn-dlp named-pkcs11[1520]: broken trust chain resolving '223.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:20:58 hn-dlp named-pkcs11[1520]: validating 224.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:20:58 hn-dlp named-pkcs11[1520]: broken trust chain resolving '224.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:00 hn-dlp named-pkcs11[1520]: validating 225.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:00 hn-dlp named-pkcs11[1520]: broken trust chain resolving '225.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:03 hn-dlp named-pkcs11[1520]: validating 226.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '226.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:06 hn-dlp named-pkcs11[1520]: validating 227.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:06 hn-dlp named-pkcs11[1520]: broken trust chain resolving '227.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:08 hn-dlp named-pkcs11[1520]: validating 228.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:08 hn-dlp named-pkcs11[1520]: broken trust chain resolving '228.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:11 hn-dlp named-pkcs11[1520]: validating 229.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:11 hn-dlp named-pkcs11[1520]: broken trust chain resolving '229.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:12 hn-dlp named-pkcs11[1520]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:12 hn-dlp named-pkcs11[1520]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:13 hn-dlp named-pkcs11[1520]: validating 230.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:13 hn-dlp named-pkcs11[1520]: broken trust chain resolving '230.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:16 hn-dlp named-pkcs11[1520]: validating 231.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:16 hn-dlp named-pkcs11[1520]: broken trust chain resolving '231.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:19 hn-dlp named-pkcs11[1520]: validating 232.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:19 hn-dlp named-pkcs11[1520]: broken trust chain resolving '232.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:21 hn-dlp named-pkcs11[1520]: validating 233.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:21 hn-dlp named-pkcs11[1520]: broken trust chain resolving '233.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:24 hn-dlp named-pkcs11[1520]: validating 234.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:24 hn-dlp named-pkcs11[1520]: broken trust chain resolving '234.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:26 hn-dlp named-pkcs11[1520]: validating 235.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:26 hn-dlp named-pkcs11[1520]: broken trust chain resolving '235.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:29 hn-dlp named-pkcs11[1520]: validating 236.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:29 hn-dlp named-pkcs11[1520]: broken trust chain resolving '236.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:32 hn-dlp named-pkcs11[1520]: validating 237.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:32 hn-dlp named-pkcs11[1520]: broken trust chain resolving '237.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:34 hn-dlp named-pkcs11[1520]: validating 238.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:34 hn-dlp named-pkcs11[1520]: broken trust chain resolving '238.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:37 hn-dlp named-pkcs11[1520]: validating 239.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:37 hn-dlp named-pkcs11[1520]: broken trust chain resolving '239.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:21:39 hn-dlp named-pkcs11[1520]: validating 240.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:39 hn-dlp named-pkcs11[1520]: broken trust chain resolving '240.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:42 hn-dlp named-pkcs11[1520]: validating 241.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:42 hn-dlp named-pkcs11[1520]: broken trust chain resolving '241.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:44 hn-dlp named-pkcs11[1520]: validating 242.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:44 hn-dlp named-pkcs11[1520]: broken trust chain resolving '242.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:21:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 26. Jan 10 08:21:46 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:21:46 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:21:47 hn-dlp named-pkcs11[1520]: validating 243.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:47 hn-dlp named-pkcs11[1520]: broken trust chain resolving '243.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:49 hn-dlp platform-python[2969]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:21:49 hn-dlp platform-python[2969]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:21:49 hn-dlp platform-python[2969]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:21:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2969]: new replica keys in LDAP: set() Jan 10 08:21:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2969]: obsolete replica keys in local HSM: set() Jan 10 08:21:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2969]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 08:21:49 hn-dlp ipa-ods-exporter[2969]: Traceback (most recent call last): Jan 10 08:21:49 hn-dlp ipa-ods-exporter[2969]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:21:49 hn-dlp ipa-ods-exporter[2969]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:21:49 hn-dlp ipa-ods-exporter[2969]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:21:49 hn-dlp ipa-ods-exporter[2969]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:21:49 hn-dlp ipa-ods-exporter[2969]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:21:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:21:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:21:50 hn-dlp named-pkcs11[1520]: validating 244.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:50 hn-dlp named-pkcs11[1520]: broken trust chain resolving '244.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:52 hn-dlp named-pkcs11[1520]: validating 245.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:52 hn-dlp named-pkcs11[1520]: broken trust chain resolving '245.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:55 hn-dlp named-pkcs11[1520]: validating 246.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:55 hn-dlp named-pkcs11[1520]: broken trust chain resolving '246.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:21:57 hn-dlp named-pkcs11[1520]: validating 247.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:21:57 hn-dlp named-pkcs11[1520]: broken trust chain resolving '247.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:22:00 hn-dlp named-pkcs11[1520]: validating 248.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:22:00 hn-dlp named-pkcs11[1520]: broken trust chain resolving '248.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:22:03 hn-dlp named-pkcs11[1520]: validating 249.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:22:03 hn-dlp named-pkcs11[1520]: broken trust chain resolving '249.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:22:05 hn-dlp named-pkcs11[1520]: validating 250.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:22:05 hn-dlp named-pkcs11[1520]: broken trust chain resolving '250.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:22:08 hn-dlp named-pkcs11[1520]: validating 251.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:22:08 hn-dlp named-pkcs11[1520]: broken trust chain resolving '251.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:22:11 hn-dlp named-pkcs11[1520]: validating 252.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:22:11 hn-dlp named-pkcs11[1520]: broken trust chain resolving '252.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:22:13 hn-dlp named-pkcs11[1520]: validating 253.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:22:13 hn-dlp named-pkcs11[1520]: broken trust chain resolving '253.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:22:16 hn-dlp named-pkcs11[1520]: validating 254.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:22:16 hn-dlp named-pkcs11[1520]: broken trust chain resolving '254.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:22:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:22:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 27. Jan 10 08:22:50 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:22:50 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:22:52 hn-dlp platform-python[2978]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:22:52 hn-dlp platform-python[2978]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:22:52 hn-dlp platform-python[2978]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:22:52 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2978]: new replica keys in LDAP: set() Jan 10 08:22:52 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2978]: obsolete replica keys in local HSM: set() Jan 10 08:22:52 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2978]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:22:52 hn-dlp ipa-ods-exporter[2978]: Traceback (most recent call last): Jan 10 08:22:52 hn-dlp ipa-ods-exporter[2978]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:22:52 hn-dlp ipa-ods-exporter[2978]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:22:52 hn-dlp ipa-ods-exporter[2978]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:22:52 hn-dlp ipa-ods-exporter[2978]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:22:52 hn-dlp ipa-ods-exporter[2978]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:22:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:22:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:23:12 hn-dlp named-pkcs11[1520]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:23:12 hn-dlp named-pkcs11[1520]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:23:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:23:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:23:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 28. Jan 10 08:23:53 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:23:53 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:23:56 hn-dlp platform-python[2987]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:23:56 hn-dlp platform-python[2987]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:23:56 hn-dlp platform-python[2987]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:23:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2987]: new replica keys in LDAP: set() Jan 10 08:23:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2987]: obsolete replica keys in local HSM: set() Jan 10 08:23:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2987]: ldap2master_replica: keys in local HSM & LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 08:23:56 hn-dlp ipa-ods-exporter[2987]: Traceback (most recent call last): Jan 10 08:23:56 hn-dlp ipa-ods-exporter[2987]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:23:56 hn-dlp ipa-ods-exporter[2987]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:23:56 hn-dlp ipa-ods-exporter[2987]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:23:56 hn-dlp ipa-ods-exporter[2987]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:23:56 hn-dlp ipa-ods-exporter[2987]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:23:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:23:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:24:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:24:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 29. Jan 10 08:24:56 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:24:56 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:24:59 hn-dlp platform-python[2999]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:24:59 hn-dlp platform-python[2999]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:24:59 hn-dlp platform-python[2999]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:24:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2999]: new replica keys in LDAP: set() Jan 10 08:24:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2999]: obsolete replica keys in local HSM: set() Jan 10 08:24:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[2999]: ldap2master_replica: keys in local HSM & LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 08:24:59 hn-dlp ipa-ods-exporter[2999]: Traceback (most recent call last): Jan 10 08:24:59 hn-dlp ipa-ods-exporter[2999]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:24:59 hn-dlp ipa-ods-exporter[2999]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:24:59 hn-dlp ipa-ods-exporter[2999]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:24:59 hn-dlp ipa-ods-exporter[2999]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:24:59 hn-dlp ipa-ods-exporter[2999]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:24:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:24:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:25:12 hn-dlp named-pkcs11[1520]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 08:25:12 hn-dlp named-pkcs11[1520]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:25:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:26:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:26:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 30. Jan 10 08:26:00 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:26:00 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:26:02 hn-dlp platform-python[3008]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:26:02 hn-dlp platform-python[3008]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:26:02 hn-dlp platform-python[3008]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:26:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[3008]: new replica keys in LDAP: set() Jan 10 08:26:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[3008]: obsolete replica keys in local HSM: set() Jan 10 08:26:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[3008]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 08:26:03 hn-dlp ipa-ods-exporter[3008]: Traceback (most recent call last): Jan 10 08:26:03 hn-dlp ipa-ods-exporter[3008]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:26:03 hn-dlp ipa-ods-exporter[3008]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:26:03 hn-dlp ipa-ods-exporter[3008]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:26:03 hn-dlp ipa-ods-exporter[3008]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:26:03 hn-dlp ipa-ods-exporter[3008]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:26:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:26:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:26:14 hn-dlp systemd-logind[744]: New session 5 of user root. Jan 10 08:26:14 hn-dlp systemd[1]: Started Session 5 of user root. Jan 10 08:26:25 hn-dlp systemd[1]: Stopping IPA key daemon... Jan 10 08:26:25 hn-dlp ipa-dnskeysyncd[2121]: ipa-dnskeysyncd: INFO Signal 15 received: Shutting down! Jan 10 08:26:26 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Succeeded. Jan 10 08:26:26 hn-dlp systemd[1]: Stopped IPA key daemon. Jan 10 08:26:26 hn-dlp systemd[1]: Stopping OpenDNSSEC Enforcer daemon... Jan 10 08:26:27 hn-dlp ods-enforcerd[2112]: [engine] enforcer shutdown Jan 10 08:26:27 hn-dlp ods-enforcerd[2112]: [engine] enforcerd (pid: 2112) stopped with exitcode 0 Jan 10 08:26:27 hn-dlp systemd[1]: ods-enforcerd.service: Succeeded. Jan 10 08:26:27 hn-dlp systemd[1]: Stopped OpenDNSSEC Enforcer daemon. Jan 10 08:26:27 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:26:27 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:26:27 hn-dlp systemd[1]: ipa-otpd.socket: Succeeded. Jan 10 08:26:27 hn-dlp systemd[1]: Closed ipa-otpd socket. Jan 10 08:26:27 hn-dlp systemd[1]: Stopping Samba Winbind Daemon... Jan 10 08:26:27 hn-dlp winbindd[2095]: [2021/01/10 08:26:27.676089, 0] ../../source3/winbindd/winbindd.c:245(winbindd_sig_term_handler) Jan 10 08:26:27 hn-dlp winbindd[2095]: Got sig[15] terminate (is_parent=1) Jan 10 08:26:27 hn-dlp winbindd[2169]: [2021/01/10 08:26:27.675649, 0] ../../source3/winbindd/winbindd.c:245(winbindd_sig_term_handler) Jan 10 08:26:27 hn-dlp winbindd[2169]: Got sig[15] terminate (is_parent=0) Jan 10 08:26:27 hn-dlp winbindd[2171]: [2021/01/10 08:26:27.677084, 0] ../../source3/winbindd/winbindd.c:245(winbindd_sig_term_handler) Jan 10 08:26:27 hn-dlp winbindd[2171]: Got sig[15] terminate (is_parent=0) Jan 10 08:26:27 hn-dlp winbindd[2170]: [2021/01/10 08:26:27.675946, 0] ../../source3/winbindd/winbindd.c:245(winbindd_sig_term_handler) Jan 10 08:26:27 hn-dlp winbindd[2170]: Got sig[15] terminate (is_parent=0) Jan 10 08:26:27 hn-dlp systemd[1]: winbind.service: Succeeded. Jan 10 08:26:27 hn-dlp systemd[1]: Stopped Samba Winbind Daemon. Jan 10 08:26:27 hn-dlp systemd[1]: Stopping Samba SMB Daemon... Jan 10 08:26:27 hn-dlp systemd[1]: smb.service: Succeeded. Jan 10 08:26:27 hn-dlp systemd[1]: Stopped Samba SMB Daemon. Jan 10 08:26:27 hn-dlp systemd[1]: Stopped target PKI Tomcat Server. Jan 10 08:26:28 hn-dlp systemd[1]: Stopping PKI Tomcat Server pki-tomcat... Jan 10 08:26:28 hn-dlp systemd[1]: Stopping IPA Custodia Service... Jan 10 08:26:28 hn-dlp systemd[1]: ipa-custodia.service: Succeeded. Jan 10 08:26:28 hn-dlp systemd[1]: Stopped IPA Custodia Service. Jan 10 08:26:28 hn-dlp systemd[1]: Stopping The Apache HTTP Server... Jan 10 08:26:28 hn-dlp server[3077]: Java virtual machine used: /usr/lib/jvm/jre-openjdk/bin/java Jan 10 08:26:28 hn-dlp server[3077]: classpath used: /usr/share/tomcat/bin/bootstrap.jar:/usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/ant.jar:/usr/share/java/ant-launcher.jar:/usr/lib/jvm/java/lib/tools.jar Jan 10 08:26:28 hn-dlp server[3077]: main class used: org.apache.catalina.startup.Bootstrap Jan 10 08:26:28 hn-dlp server[3077]: flags used: -Dcom.redhat.fips=false Jan 10 08:26:28 hn-dlp server[3077]: options used: -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager Jan 10 08:26:28 hn-dlp server[3077]: arguments used: stop Jan 10 08:26:31 hn-dlp platform-python[3065]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:26:31 hn-dlp platform-python[3065]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:26:31 hn-dlp platform-python[3065]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:26:31 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[3065]: new replica keys in LDAP: set() Jan 10 08:26:31 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[3065]: obsolete replica keys in local HSM: set() Jan 10 08:26:31 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[3065]: ldap2master_replica: keys in local HSM & LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 08:26:31 hn-dlp ipa-ods-exporter[3065]: Traceback (most recent call last): Jan 10 08:26:31 hn-dlp ipa-ods-exporter[3065]: File "/usr/libexec/ipa/ipa-ods-exporter", line 702, in <module> Jan 10 08:26:31 hn-dlp ipa-ods-exporter[3065]: master2ldap_master_keys_sync(ldapkeydb, localhsm) Jan 10 08:26:31 hn-dlp ipa-ods-exporter[3065]: File "/usr/libexec/ipa/ipa-ods-exporter", line 378, in master2ldap_master_keys_sync Jan 10 08:26:31 hn-dlp ipa-ods-exporter[3065]: mkey_local = localhsm.find_keys(id=mkey_id).popitem()[1] Jan 10 08:26:31 hn-dlp ipa-ods-exporter[3065]: KeyError: 'popitem(): dictionary is empty' Jan 10 08:26:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:26:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:26:36 hn-dlp systemd[1]: httpd.service: Succeeded. Jan 10 08:26:36 hn-dlp systemd[1]: Stopped The Apache HTTP Server. Jan 10 08:26:36 hn-dlp systemd[1]: Stopping Berkeley Internet Name Domain (DNS) with native PKCS#11... Jan 10 08:26:36 hn-dlp named-pkcs11[1520]: received control channel command 'stop' Jan 10 08:26:36 hn-dlp named-pkcs11[1520]: shutting down: flushing changes Jan 10 08:26:36 hn-dlp named-pkcs11[1520]: stopping command channel on 127.0.0.1#953 Jan 10 08:26:36 hn-dlp named-pkcs11[1520]: stopping command channel on ::1#953 Jan 10 08:26:37 hn-dlp named-pkcs11[1520]: unloading DynDB instance 'ipa' Jan 10 08:26:37 hn-dlp systemd[1]: pki-tomcatd@pki-tomcat.service: Succeeded. Jan 10 08:26:37 hn-dlp systemd[1]: Stopped PKI Tomcat Server pki-tomcat. Jan 10 08:26:37 hn-dlp named-pkcs11[1520]: zone 177.19.172.in-addr.arpa/IN: shutting down Jan 10 08:26:37 hn-dlp named-pkcs11[1520]: zone 187.19.172.in-addr.arpa/IN: shutting down Jan 10 08:26:37 hn-dlp named-pkcs11[1520]: zone 195.19.172.in-addr.arpa/IN: shutting down Jan 10 08:26:37 hn-dlp named-pkcs11[1520]: zone 197.19.172.in-addr.arpa/IN: shutting down Jan 10 08:26:37 hn-dlp named-pkcs11[1520]: zone ipa.example.local/IN: shutting down Jan 10 08:26:37 hn-dlp named-pkcs11[1520]: no longer listening on ::#53 Jan 10 08:26:37 hn-dlp named-pkcs11[1520]: no longer listening on 127.0.0.1#53 Jan 10 08:26:37 hn-dlp named-pkcs11[1520]: no longer listening on 172.19.187.2#53 Jan 10 08:26:38 hn-dlp named-pkcs11[1520]: exiting Jan 10 08:26:39 hn-dlp systemd[1]: named-pkcs11.service: Succeeded. Jan 10 08:26:39 hn-dlp systemd[1]: Stopped Berkeley Internet Name Domain (DNS) with native PKCS#11. Jan 10 08:26:39 hn-dlp systemd[1]: Stopping Kerberos 5 Password-changing and Administration... Jan 10 08:26:39 hn-dlp systemd[1]: kadmin.service: Succeeded. Jan 10 08:26:39 hn-dlp systemd[1]: Stopped Kerberos 5 Password-changing and Administration. Jan 10 08:26:39 hn-dlp systemd[1]: Stopping Kerberos 5 KDC... Jan 10 08:26:39 hn-dlp systemd[1]: krb5kdc.service: Succeeded. Jan 10 08:26:39 hn-dlp systemd[1]: Stopped Kerberos 5 KDC. Jan 10 08:26:39 hn-dlp systemd[1]: Stopping 389 Directory Server IPA-TECIN-NET.... Jan 10 08:26:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:08:26:39.781790116 +0100] - INFO - op_thread_cleanup - slapd shutting down - signaling operation threads - op stack size 13 max work q size 7 max work q stack size 7 Jan 10 08:26:39 hn-dlp ns-slapd[1450]: [10/Jan/2021:08:26:39.820551148 +0100] - INFO - slapd_daemon - slapd shutting down - closing down internal subsystems and plugins Jan 10 08:27:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:27:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 31. Jan 10 08:27:32 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:27:32 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: Traceback (most recent call last): Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1078, in error_handler Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: yield Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: '', auth_tokens, server_controls, client_controls) Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 465, in sasl_interactive_bind_s Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: return self._ldap_call(self._l.sasl_interactive_bind_s,who,auth,RequestControlTuples(serverctrls),RequestControlTuples(clientctrls),sasl_flags) Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 329, in _ldap_call Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: reraise(exc_type, exc_value, exc_traceback) Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: File "/usr/lib64/python3.6/site-packages/ldap/compat.py", line 44, in reraise Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: raise exc_value Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 313, in _ldap_call Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: result = func(*args,**kwargs) Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: ldap.SERVER_DOWN: {'desc': "Can't contact LDAP server", 'errno': 111, 'info': 'Connection refused'} Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: During handling of the above exception, another exception occurred: Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: Traceback (most recent call last): Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: File "/usr/libexec/ipa/ipa-ods-exporter", line 689, in <module> Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: ldap.gssapi_bind() Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: '', auth_tokens, server_controls, client_controls) Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: File "/usr/lib64/python3.6/contextlib.py", line 99, in __exit__ Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: self.gen.throw(type, value, traceback) Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1132, in error_handler Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: error=info) Jan 10 08:27:34 hn-dlp ipa-ods-exporter[3136]: ipalib.errors.NetworkError: cannot connect to 'ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket': Connection refused Jan 10 08:27:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:27:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:27:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:27:46 hn-dlp ns-slapd[1450]: [10/Jan/2021:08:27:46.167203087 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=caTonf-dlp.ipa.example.local" (nf-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 08:27:46 hn-dlp ns-slapd[1450]: [10/Jan/2021:08:27:46.904244706 +0100] - INFO - bdb_pre_close - Waiting for 4 database threads to stop Jan 10 08:27:47 hn-dlp ns-slapd[1450]: [10/Jan/2021:08:27:47.530516736 +0100] - INFO - bdb_pre_close - All database threads now stopped Jan 10 08:27:47 hn-dlp ns-slapd[1450]: [10/Jan/2021:08:27:47.921638751 +0100] - INFO - ldbm_back_instance_set_destructor - Set of instances destroyed Jan 10 08:27:47 hn-dlp ns-slapd[1450]: [10/Jan/2021:08:27:47.926669824 +0100] - INFO - connection_post_shutdown_cleanup - slapd shutting down - freed 7 work q stack objects - freed 13 op stack objects Jan 10 08:27:47 hn-dlp ns-slapd[1450]: [10/Jan/2021:08:27:47.927514532 +0100] - INFO - main - slapd stopped. Jan 10 08:27:48 hn-dlp systemd[1]: dirsrv@IPA-TECIN-NET.service: Succeeded. Jan 10 08:27:48 hn-dlp systemd[1]: Stopped 389 Directory Server IPA-TECIN-NET.. Jan 10 08:28:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:28:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 32. Jan 10 08:28:35 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:28:35 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: Traceback (most recent call last): Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1078, in error_handler Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: yield Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: '', auth_tokens, server_controls, client_controls) Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 465, in sasl_interactive_bind_s Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: return self._ldap_call(self._l.sasl_interactive_bind_s,who,auth,RequestControlTuples(serverctrls),RequestControlTuples(clientctrls),sasl_flags) Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 329, in _ldap_call Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: reraise(exc_type, exc_value, exc_traceback) Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: File "/usr/lib64/python3.6/site-packages/ldap/compat.py", line 44, in reraise Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: raise exc_value Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 313, in _ldap_call Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: result = func(*args,**kwargs) Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: ldap.SERVER_DOWN: {'desc': "Can't contact LDAP server", 'errno': 111, 'info': 'Connection refused'} Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: During handling of the above exception, another exception occurred: Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: Traceback (most recent call last): Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: File "/usr/libexec/ipa/ipa-ods-exporter", line 689, in <module> Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: ldap.gssapi_bind() Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: '', auth_tokens, server_controls, client_controls) Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: File "/usr/lib64/python3.6/contextlib.py", line 99, in __exit__ Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: self.gen.throw(type, value, traceback) Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1132, in error_handler Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: error=info) Jan 10 08:28:38 hn-dlp ipa-ods-exporter[3147]: ipalib.errors.NetworkError: cannot connect to 'ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket': Connection refused Jan 10 08:28:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:28:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:29:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:29:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:29:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 33. Jan 10 08:29:38 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:29:38 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: Traceback (most recent call last): Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1078, in error_handler Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: yield Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: '', auth_tokens, server_controls, client_controls) Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 465, in sasl_interactive_bind_s Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: return self._ldap_call(self._l.sasl_interactive_bind_s,who,auth,RequestControlTuples(serverctrls),RequestControlTuples(clientctrls),sasl_flags) Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 329, in _ldap_call Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: reraise(exc_type, exc_value, exc_traceback) Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: File "/usr/lib64/python3.6/site-packages/ldap/compat.py", line 44, in reraise Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: raise exc_value Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 313, in _ldap_call Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: result = func(*args,**kwargs) Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: ldap.SERVER_DOWN: {'desc': "Can't contact LDAP server", 'errno': 111, 'info': 'Connection refused'} Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: During handling of the above exception, another exception occurred: Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: Traceback (most recent call last): Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: File "/usr/libexec/ipa/ipa-ods-exporter", line 689, in <module> Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: ldap.gssapi_bind() Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: '', auth_tokens, server_controls, client_controls) Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: File "/usr/lib64/python3.6/contextlib.py", line 99, in __exit__ Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: self.gen.throw(type, value, traceback) Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1132, in error_handler Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: error=info) Jan 10 08:29:41 hn-dlp ipa-ods-exporter[3154]: ipalib.errors.NetworkError: cannot connect to 'ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket': Connection refused Jan 10 08:29:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:29:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:30:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:30:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 34. Jan 10 08:30:41 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:30:41 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:30:43 hn-dlp systemd[1]: Created slice User Slice of UID 2002. Jan 10 08:30:43 hn-dlp systemd[1]: Started /run/user/2002 mount wrapper. Jan 10 08:30:43 hn-dlp systemd[1]: Starting User Manager for UID 2002... Jan 10 08:30:43 hn-dlp systemd[1]: Started Session 6 of user svcforeman. Jan 10 08:30:43 hn-dlp systemd-logind[744]: New session 6 of user svcforeman. Jan 10 08:30:43 hn-dlp systemd[3171]: Reached target Paths. Jan 10 08:30:43 hn-dlp systemd[3171]: Starting D-Bus User Message Bus Socket. Jan 10 08:30:43 hn-dlp systemd[3171]: Started Mark boot as successful after the user session has run 2 minutes. Jan 10 08:30:43 hn-dlp systemd[3171]: Reached target Timers. Jan 10 08:30:43 hn-dlp systemd[3171]: Listening on D-Bus User Message Bus Socket. Jan 10 08:30:43 hn-dlp systemd[3171]: Reached target Sockets. Jan 10 08:30:43 hn-dlp systemd[3171]: Reached target Basic System. Jan 10 08:30:43 hn-dlp systemd[3171]: Reached target Default. Jan 10 08:30:43 hn-dlp systemd[3171]: Startup finished in 53ms. Jan 10 08:30:43 hn-dlp systemd[1]: Started User Manager for UID 2002. Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: Traceback (most recent call last): Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1078, in error_handler Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: yield Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: '', auth_tokens, server_controls, client_controls) Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 465, in sasl_interactive_bind_s Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: return self._ldap_call(self._l.sasl_interactive_bind_s,who,auth,RequestControlTuples(serverctrls),RequestControlTuples(clientctrls),sasl_flags) Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 329, in _ldap_call Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: reraise(exc_type, exc_value, exc_traceback) Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: File "/usr/lib64/python3.6/site-packages/ldap/compat.py", line 44, in reraise Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: raise exc_value Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 313, in _ldap_call Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: result = func(*args,**kwargs) Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: ldap.SERVER_DOWN: {'desc': "Can't contact LDAP server", 'errno': 111, 'info': 'Connection refused'} Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: During handling of the above exception, another exception occurred: Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: Traceback (most recent call last): Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: File "/usr/libexec/ipa/ipa-ods-exporter", line 689, in <module> Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: ldap.gssapi_bind() Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: '', auth_tokens, server_controls, client_controls) Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: File "/usr/lib64/python3.6/contextlib.py", line 99, in __exit__ Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: self.gen.throw(type, value, traceback) Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1132, in error_handler Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: error=info) Jan 10 08:30:44 hn-dlp ipa-ods-exporter[3161]: ipalib.errors.NetworkError: cannot connect to 'ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket': Connection refused Jan 10 08:30:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:30:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:30:46 hn-dlp platform-python[3335]: ansible-setup Invoked with gather_timeout=10 gather_subset=['all'] filter=* fact_path=/etc/ansible/facts.d Jan 10 08:31:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:31:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:31:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 35. Jan 10 08:31:44 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:31:44 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: Traceback (most recent call last): Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1078, in error_handler Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: yield Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: '', auth_tokens, server_controls, client_controls) Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 465, in sasl_interactive_bind_s Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: return self._ldap_call(self._l.sasl_interactive_bind_s,who,auth,RequestControlTuples(serverctrls),RequestControlTuples(clientctrls),sasl_flags) Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 329, in _ldap_call Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: reraise(exc_type, exc_value, exc_traceback) Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: File "/usr/lib64/python3.6/site-packages/ldap/compat.py", line 44, in reraise Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: raise exc_value Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 313, in _ldap_call Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: result = func(*args,**kwargs) Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: ldap.SERVER_DOWN: {'desc': "Can't contact LDAP server", 'errno': 111, 'info': 'Connection refused'} Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: During handling of the above exception, another exception occurred: Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: Traceback (most recent call last): Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: File "/usr/libexec/ipa/ipa-ods-exporter", line 689, in <module> Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: ldap.gssapi_bind() Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: '', auth_tokens, server_controls, client_controls) Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: File "/usr/lib64/python3.6/contextlib.py", line 99, in __exit__ Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: self.gen.throw(type, value, traceback) Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1132, in error_handler Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: error=info) Jan 10 08:31:47 hn-dlp ipa-ods-exporter[3441]: ipalib.errors.NetworkError: cannot connect to 'ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket': Connection refused Jan 10 08:31:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:31:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:31:51 hn-dlp systemd[1]: session-6.scope: Succeeded. Jan 10 08:31:51 hn-dlp systemd-logind[744]: Session 6 logged out. Waiting for processes to exit. Jan 10 08:31:51 hn-dlp systemd-logind[744]: Removed session 6. Jan 10 08:31:51 hn-dlp systemd[1]: Stopping User Manager for UID 2002... Jan 10 08:31:51 hn-dlp systemd[3171]: Stopped target Default. Jan 10 08:31:51 hn-dlp systemd[3171]: Stopped target Basic System. Jan 10 08:31:51 hn-dlp systemd[3171]: Stopped target Timers. Jan 10 08:31:51 hn-dlp systemd[3171]: grub-boot-success.timer: Succeeded. Jan 10 08:31:51 hn-dlp systemd[3171]: Stopped Mark boot as successful after the user session has run 2 minutes. Jan 10 08:31:51 hn-dlp systemd[3171]: Stopped target Sockets. Jan 10 08:31:51 hn-dlp systemd[3171]: dbus.socket: Succeeded. Jan 10 08:31:51 hn-dlp systemd[3171]: Closed D-Bus User Message Bus Socket. Jan 10 08:31:51 hn-dlp systemd[3171]: Stopped target Paths. Jan 10 08:31:51 hn-dlp systemd[3171]: Reached target Shutdown. Jan 10 08:31:51 hn-dlp systemd[3171]: Starting Exit the Session... Jan 10 08:31:51 hn-dlp systemd[1]: user@2002.service: Succeeded. Jan 10 08:31:51 hn-dlp systemd[1]: Stopped User Manager for UID 2002. Jan 10 08:31:51 hn-dlp systemd[1]: Stopping /run/user/2002 mount wrapper... Jan 10 08:31:51 hn-dlp systemd[1]: Removed slice User Slice of UID 2002. Jan 10 08:31:51 hn-dlp systemd[2804]: run-user-2002.mount: Succeeded. Jan 10 08:31:51 hn-dlp systemd[1]: run-user-2002.mount: Succeeded. Jan 10 08:31:51 hn-dlp systemd[1]: user-runtime-dir@2002.service: Succeeded. Jan 10 08:31:51 hn-dlp systemd[1]: Stopped /run/user/2002 mount wrapper. Jan 10 08:32:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:32:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 36. Jan 10 08:32:47 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:32:47 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: Traceback (most recent call last): Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1078, in error_handler Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: yield Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: '', auth_tokens, server_controls, client_controls) Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 465, in sasl_interactive_bind_s Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: return self._ldap_call(self._l.sasl_interactive_bind_s,who,auth,RequestControlTuples(serverctrls),RequestControlTuples(clientctrls),sasl_flags) Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 329, in _ldap_call Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: reraise(exc_type, exc_value, exc_traceback) Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: File "/usr/lib64/python3.6/site-packages/ldap/compat.py", line 44, in reraise Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: raise exc_value Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 313, in _ldap_call Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: result = func(*args,**kwargs) Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: ldap.SERVER_DOWN: {'desc': "Can't contact LDAP server", 'errno': 111, 'info': 'Connection refused'} Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: During handling of the above exception, another exception occurred: Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: Traceback (most recent call last): Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: File "/usr/libexec/ipa/ipa-ods-exporter", line 689, in <module> Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: ldap.gssapi_bind() Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: '', auth_tokens, server_controls, client_controls) Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: File "/usr/lib64/python3.6/contextlib.py", line 99, in __exit__ Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: self.gen.throw(type, value, traceback) Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1132, in error_handler Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: error=info) Jan 10 08:32:49 hn-dlp ipa-ods-exporter[3460]: ipalib.errors.NetworkError: cannot connect to 'ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket': Connection refused Jan 10 08:32:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:32:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:33:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:33:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:33:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 37. Jan 10 08:33:50 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:33:50 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: Traceback (most recent call last): Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1078, in error_handler Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: yield Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: '', auth_tokens, server_controls, client_controls) Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 465, in sasl_interactive_bind_s Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: return self._ldap_call(self._l.sasl_interactive_bind_s,who,auth,RequestControlTuples(serverctrls),RequestControlTuples(clientctrls),sasl_flags) Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 329, in _ldap_call Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: reraise(exc_type, exc_value, exc_traceback) Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: File "/usr/lib64/python3.6/site-packages/ldap/compat.py", line 44, in reraise Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: raise exc_value Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 313, in _ldap_call Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: result = func(*args,**kwargs) Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: ldap.SERVER_DOWN: {'desc': "Can't contact LDAP server", 'errno': 111, 'info': 'Connection refused'} Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: During handling of the above exception, another exception occurred: Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: Traceback (most recent call last): Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: File "/usr/libexec/ipa/ipa-ods-exporter", line 689, in <module> Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: ldap.gssapi_bind() Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: '', auth_tokens, server_controls, client_controls) Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: File "/usr/lib64/python3.6/contextlib.py", line 99, in __exit__ Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: self.gen.throw(type, value, traceback) Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1132, in error_handler Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: error=info) Jan 10 08:33:52 hn-dlp ipa-ods-exporter[3467]: ipalib.errors.NetworkError: cannot connect to 'ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket': Connection refused Jan 10 08:33:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:33:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:33:55 hn-dlp systemd[1]: Starting 389 Directory Server IPA-TECIN-NET.... Jan 10 08:33:56 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:56.616823004 +0100] - INFO - slapd_extract_cert - CA CERT NAME: IPA.example.local IPA CA Jan 10 08:33:56 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:56.618088397 +0100] - INFO - slapd_extract_cert - CA CERT NAME: DC=tecin,DC=net,E=info@example.local,CN=TecIn-CA Jan 10 08:33:56 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:56.619553631 +0100] - WARN - Security Initialization - SSL alert: Sending pin request to SVRCore. You may need to run systemd-tty-ask-password-agent to provide the password. Jan 10 08:33:56 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:56.901488407 +0100] - INFO - slapd_extract_cert - SERVER CERT NAME: Server-Cert Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.495574090 +0100] - INFO - Security Initialization - SSL info: Enabling default cipher set. Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.496288431 +0100] - INFO - Security Initialization - SSL info: Configured NSS Ciphers Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.502659005 +0100] - INFO - Security Initialization - SSL info: #011TLS_AES_128_GCM_SHA256: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.504123320 +0100] - INFO - Security Initialization - SSL info: #011TLS_CHACHA20_POLY1305_SHA256: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.508414078 +0100] - INFO - Security Initialization - SSL info: #011TLS_AES_256_GCM_SHA384: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.512128406 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.516215570 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.518886929 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.520482590 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.521052341 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.543906044 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.544620123 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.545796697 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.546319093 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.547360559 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.548029506 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.548889198 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.555152741 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.571106013 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.571682096 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.572537116 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_128_CBC_SHA: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.574674549 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.578739567 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_256_CBC_SHA: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.582875705 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_256_CBC_SHA256: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.586907858 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.602997097 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.603781221 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_128_CBC_SHA: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.604863586 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.606615325 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_256_CBC_SHA: enabled Jan 10 08:33:57 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:57.610745884 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_256_CBC_SHA256: enabled Jan 10 08:33:58 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:58.208398847 +0100] - INFO - Security Initialization - slapd_ssl_init2 - Configured SSL version range: min: TLS1.2, max: TLS1.3 Jan 10 08:33:58 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:58.210286555 +0100] - INFO - Security Initialization - slapd_ssl_init2 - NSS adjusted SSL version range: min: TLS1.2, max: TLS1.3 Jan 10 08:33:58 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:58.211368816 +0100] - INFO - main - 389-Directory/1.4.3.8 B2020.357.1921 starting up Jan 10 08:33:58 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:58.212229372 +0100] - INFO - main - Setting the maximum file descriptor limit to: 262144 Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.185140245 +0100] - INFO - PBKDF2_SHA256 - Based on CPU performance, chose 2048 rounds Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.189004356 +0100] - INFO - ldbm_instance_config_cachememsize_set - force a minimal value 512000 Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.195876593 +0100] - INFO - ldbm_instance_config_cachememsize_set - force a minimal value 512000 Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.201834204 +0100] - INFO - ldbm_instance_config_cachememsize_set - force a minimal value 512000 Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.207714206 +0100] - NOTICE - ldbm_back_start - found 1343712k physical memory Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.208851267 +0100] - NOTICE - ldbm_back_start - found 859400k available Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.209720551 +0100] - NOTICE - ldbm_back_start - cache autosizing: db cache: 33592k Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.210168617 +0100] - NOTICE - ldbm_back_start - cache autosizing: userRoot entry cache (3 total): 65536k Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.210799387 +0100] - NOTICE - ldbm_back_start - cache autosizing: userRoot dn cache (3 total): 65536k Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.211655221 +0100] - NOTICE - ldbm_back_start - cache autosizing: ipaca entry cache (3 total): 65536k Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.212360195 +0100] - NOTICE - ldbm_back_start - cache autosizing: ipaca dn cache (3 total): 65536k Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.212998486 +0100] - NOTICE - ldbm_back_start - cache autosizing: changelog entry cache (3 total): 65536k Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.213825508 +0100] - NOTICE - ldbm_back_start - cache autosizing: changelog dn cache (3 total): 65536k Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.214636947 +0100] - NOTICE - ldbm_back_start - total cache size: 430172405 B; Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.500212414 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher AES Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.501140304 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.766007896 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher 3DES Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.767214041 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 08:33:59 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:33:59.767908437 +0100] - ERR - attrcrypt_init - All prepared ciphers are not available. Please disable attribute encryption. Jan 10 08:34:00 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:00.042931120 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher AES Jan 10 08:34:00 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:00.044098686 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 08:34:00 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:00.303001496 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher 3DES Jan 10 08:34:00 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:00.304147971 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 08:34:00 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:00.304762658 +0100] - ERR - attrcrypt_init - All prepared ciphers are not available. Please disable attribute encryption. Jan 10 08:34:00 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:00.974091304 +0100] - ERR - schema-compat-plugin - scheduled schema-compat-plugin tree scan in about 5 seconds after the server startup! Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.015046200 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=groups,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.016365361 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=computers,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.019478577 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=ng,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.021633462 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target ou=sudoers,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.025338038 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=users,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.029434087 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.033564067 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.037420414 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.041377318 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.045563225 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.049332975 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.050088845 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.050847128 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.051412805 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.051915753 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.052524258 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.084556196 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.085567328 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.183298143 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=automember rebuild membership,cn=tasks,cn=config does not exist Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.188855891 +0100] - ERR - cos-plugin - cos_dn_defs_cb - Skipping CoS Definition cn=Password Policy,cn=accounts,dc=ipa,dc=tecin,dc=net--no CoS Templates found, which should be added before the CoS Definition. Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.245123039 +0100] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/hn-dlp.ipa.example.local@IPA.example.local] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC for requested realm) Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.247612573 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=meToha-dlp.ipa.example.local" (ha-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.248941406 +0100] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/hn-dlp.ipa.example.local@IPA.example.local] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC for requested realm) Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.250234704 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=caToha-dlp.ipa.example.local" (ha-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.253221169 +0100] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/hn-dlp.ipa.example.local@IPA.example.local] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC for requested realm) Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.259633609 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=caTonf-dlp.ipa.example.local" (nf-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.264990912 +0100] - INFO - slapd_daemon - slapd started. Listening on All Interfaces port 389 for LDAP requests Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.266026475 +0100] - INFO - slapd_daemon - Listening on All Interfaces port 636 for LDAPS requests Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.266562629 +0100] - INFO - slapd_daemon - Listening on /var/run/slapd-IPA-TECIN-NET.socket for LDAPI requests Jan 10 08:34:01 hn-dlp systemd[1]: Started 389 Directory Server IPA-TECIN-NET.. Jan 10 08:34:01 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:01.312902472 +0100] - ERR - schema-compat-plugin - schema-compat-plugin tree scan will start in about 5 seconds! Jan 10 08:34:01 hn-dlp systemd[1]: Starting Kerberos 5 KDC... Jan 10 08:34:01 hn-dlp systemd[1]: krb5kdc.service: Can't open PID file /var/run/krb5kdc.pid (yet?) after start: No such file or directory Jan 10 08:34:01 hn-dlp systemd[1]: Started Kerberos 5 KDC. Jan 10 08:34:01 hn-dlp systemd[1]: Starting Kerberos 5 Password-changing and Administration... Jan 10 08:34:02 hn-dlp systemd[1]: Started Kerberos 5 Password-changing and Administration. Jan 10 08:34:02 hn-dlp systemd[1]: Starting Generate rndc key for BIND (DNS)... Jan 10 08:34:02 hn-dlp systemd[1]: named-setup-rndc.service: Succeeded. Jan 10 08:34:02 hn-dlp systemd[1]: Started Generate rndc key for BIND (DNS). Jan 10 08:34:02 hn-dlp systemd[1]: Starting Berkeley Internet Name Domain (DNS) with native PKCS#11... Jan 10 08:34:02 hn-dlp bash[3554]: zone localhost.localdomain/IN: loaded serial 0 Jan 10 08:34:02 hn-dlp bash[3554]: zone localhost/IN: loaded serial 0 Jan 10 08:34:02 hn-dlp bash[3554]: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 0 Jan 10 08:34:02 hn-dlp bash[3554]: zone 1.0.0.127.in-addr.arpa/IN: loaded serial 0 Jan 10 08:34:02 hn-dlp bash[3554]: zone 0.in-addr.arpa/IN: loaded serial 0 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: starting BIND 9.11.20-RedHat-9.11.20-5.el8 (Extended Support Version) <id:f3d1d66> Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: running on Linux x86_64 4.18.0-240.1.1.el8_3.x86_64 #1 SMP Thu Nov 19 17:20:08 UTC 2020 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: built with '--build=x86_64-redhat-linux-gnu' '--host=x86_64-redhat-linux-gnu' '--program-prefix=' '--disable-dependency-tracking' '--prefix=/usr' '--exec-prefix=/usr' '--bindir=/usr/bin' '--sbindir=/usr/sbin' '--sysconfdir=/etc' '--datadir=/usr/share' '--includedir=/usr/include' '--libdir=/usr/lib64' '--libexecdir=/usr/libexec' '--sharedstatedir=/var/lib' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--with-python=/usr/libexec/platform-python' '--with-libtool' '--localstatedir=/var' '--enable-threads' '--enable-ipv6' '--enable-filter-aaaa' '--with-pic' '--disable-static' '--includedir=/usr/include/bind9' '--with-tuning=large' '--with-libidn2' '--enable-openssl-hash' '--with-geoip2' '--enable-native-pkcs11' '--with-pkcs11=/usr/lib64/pkcs11/libsofthsm2.so' '--with-dlopen=yes' '--with-dlz-ldap=yes' '--with-dlz-postgres=yes' '--with-dlz-mysql=yes' '--with-dlz-filesystem=yes' '--with-dlz-bdb=yes' '--with-gssapi=yes' '--disable-isc-spnego' '--with-lmdb=no' '--with-cmocka' '--enable-fixed-rrset' '--with-docbook-xsl=/usr/share/sgml/docbook/xsl-stylesheets' '--enable-full-report' 'build_alias=x86_64-redhat-linux-gnu' 'host_alias=x86_64-redhat-linux-gnu' 'CFLAGS= -O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection' 'LDFLAGS=-Wl,-z,relro -Wl,-z,now -specs=/usr/lib/rpm/redhat/redhat-hardened-ld' 'CPPFLAGS= -DDIG_SIGCHASE' 'PKG_CONFIG_PATH=:/usr/lib64/pkgconfig:/usr/share/pkgconfig' Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: running as: named-pkcs11 -u named -c /etc/named.conf Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: compiled by GCC 8.3.1 20191121 (Red Hat 8.3.1-5) Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: compiled with libxml2 version: 2.9.7 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: linked to libxml2 version: 20907 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: compiled with zlib version: 1.2.11 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: linked to zlib version: 1.2.11 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: threads support is enabled Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: ---------------------------------------------------- Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: BIND 9 is maintained by Internet Systems Consortium, Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: Inc. (ISC), a non-profit 501(c)(3) public-benefit Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: corporation. Support and training for BIND 9 are Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: available at https://www.isc.org/support Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: ---------------------------------------------------- Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: adjusted limit on open files from 262144 to 1048576 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: found 4 CPUs, using 4 worker threads Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: using 3 UDP listeners per interface Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: using up to 21000 sockets Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: loading configuration from '/etc/named.conf' Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: unable to open '/etc/bind.keys'; using built-in keys instead Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: looking for GeoIP2 databases in '/usr/share/GeoIP' Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-Country.mmdb' Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-City.mmdb' Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: using default UDP/IPv4 port range: [32768, 60999] Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: using default UDP/IPv6 port range: [32768, 60999] Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: listening on IPv6 interfaces, port 53 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: listening on IPv4 interface lo, 127.0.0.1#53 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: listening on IPv4 interface ens18, 172.19.187.2#53 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: generating session key for dynamic DNS Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: sizing zone task pool based on 6 zones Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: none:104: 'max-cache-size 90%' - setting to 1180MB (out of 1312MB) Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: set up managed keys zone for view _default, file '/var/named/dynamic/managed-keys.bind' Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: loading DynDB instance 'ipa' driver '/usr/lib64/bind/ldap.so' Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: bind-dyndb-ldap version 11.3 compiled at 16:06:42 Sep 1 2020, compiler 8.3.1 20191121 (Red Hat 8.3.1-5) Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 10.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 16.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 17.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 18.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 19.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 20.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 21.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 22.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 23.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 24.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 25.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 26.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 27.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 28.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 29.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 30.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 31.172.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 168.192.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 64.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 65.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 66.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 67.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 68.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 69.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 70.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 71.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 72.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 73.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 74.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 75.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 76.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 77.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 78.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 79.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 80.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 81.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 82.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 83.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 84.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 85.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 86.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 87.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 88.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 89.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 90.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 91.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 92.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 93.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 94.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 95.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 96.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 97.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 98.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 99.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 100.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 101.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 102.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 103.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 104.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 105.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 106.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 107.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 108.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 109.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 110.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 111.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 112.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 113.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 114.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 115.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 116.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 117.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 118.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 119.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 120.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 121.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 122.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 123.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 124.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 125.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 126.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 127.100.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 127.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 254.169.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 2.0.192.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 100.51.198.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 113.0.203.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 255.255.255.255.IN-ADDR.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: D.F.IP6.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 8.E.F.IP6.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 9.E.F.IP6.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: A.E.F.IP6.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: B.E.F.IP6.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: 8.B.D.0.1.0.0.2.IP6.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: EMPTY.AS112.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: automatic empty zone: HOME.ARPA Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: none:104: 'max-cache-size 90%' - setting to 1180MB (out of 1312MB) Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: configuring command channel from '/etc/rndc.key' Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: command channel listening on 127.0.0.1#953 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: configuring command channel from '/etc/rndc.key' Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: command channel listening on ::1#953 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: managed-keys-zone: journal file is out of date: removing journal file Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: managed-keys-zone: loaded serial 227 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: shutting down automatic empty zones to enable forwarding for domain '.' Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 0.in-addr.arpa/IN: loaded serial 0 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 0 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone localhost/IN: loaded serial 0 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 100.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 101.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 102.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 1.0.0.127.in-addr.arpa/IN: loaded serial 0 Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone localhost.localdomain/IN: loaded serial 0 Jan 10 08:34:02 hn-dlp systemd[1]: Started Berkeley Internet Name Domain (DNS) with native PKCS#11. Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 103.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 104.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 105.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 106.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 107.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 108.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 109.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: all zones loaded Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 110.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 111.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 112.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 113.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 114.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 115.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 116.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 117.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 118.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 119.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 120.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 121.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 122.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 123.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 124.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 125.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 126.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 127.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 254.169.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 2.0.192.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 100.51.198.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 113.0.203.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 255.255.255.255.IN-ADDR.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone D.F.IP6.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 8.E.F.IP6.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 9.E.F.IP6.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone A.E.F.IP6.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone B.E.F.IP6.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone 8.B.D.0.1.0.0.2.IP6.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: zone EMPTY.AS112.ARPA/IN: shutting down Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: running Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: LDAP configuration for instance 'ipa' synchronized Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: LDAP data for instance 'ipa' are being synchronized, please ignore message 'all zones loaded' Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: managed-keys-zone: Key 20326 for zone . acceptance timer complete: key now trusted Jan 10 08:34:02 hn-dlp systemd[1]: Starting One-time temporary TLS key generation for httpd.service... Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: forward zone 'int.example.local': loaded Jan 10 08:34:02 hn-dlp named-pkcs11[3558]: forward zone 'srv.example.local': loaded Jan 10 08:34:02 hn-dlp systemd[1]: httpd-init.service: Succeeded. Jan 10 08:34:03 hn-dlp systemd[1]: Started One-time temporary TLS key generation for httpd.service. Jan 10 08:34:03 hn-dlp named-pkcs11[3558]: zone 177.19.172.in-addr.arpa/IN: loaded serial 1610264042 Jan 10 08:34:03 hn-dlp systemd[1]: Starting The Apache HTTP Server... Jan 10 08:34:03 hn-dlp named-pkcs11[3558]: zone 187.19.172.in-addr.arpa/IN: loaded serial 1610264042 Jan 10 08:34:03 hn-dlp named-pkcs11[3558]: zone 177.19.172.in-addr.arpa/IN: sending notifies (serial 1610264042) Jan 10 08:34:03 hn-dlp named-pkcs11[3558]: zone 187.19.172.in-addr.arpa/IN: sending notifies (serial 1610264042) Jan 10 08:34:03 hn-dlp named-pkcs11[3558]: zone 195.19.172.in-addr.arpa/IN: loaded serial 1610264042 Jan 10 08:34:03 hn-dlp named-pkcs11[3558]: zone 197.19.172.in-addr.arpa/IN: loaded serial 1610264042 Jan 10 08:34:03 hn-dlp named-pkcs11[3558]: zone ipa.example.local/IN: loaded serial 1610264042 Jan 10 08:34:03 hn-dlp named-pkcs11[3558]: 5 master zones from LDAP instance 'ipa' loaded (5 zones defined, 0 inactive, 0 failed to load) Jan 10 08:34:03 hn-dlp named-pkcs11[3558]: zone 195.19.172.in-addr.arpa/IN: sending notifies (serial 1610264042) Jan 10 08:34:03 hn-dlp named-pkcs11[3558]: zone 197.19.172.in-addr.arpa/IN: sending notifies (serial 1610264042) Jan 10 08:34:03 hn-dlp named-pkcs11[3558]: zone ipa.example.local/IN: sending notifies (serial 1610264042) Jan 10 08:34:03 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:03.035085526 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=meTonf-dlp.ipa.example.local" (nf-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 08:34:03 hn-dlp ipa-httpd-kdcproxy[3573]: ipa: INFO: KDC proxy enabled Jan 10 08:34:03 hn-dlp ipa-httpd-kdcproxy[3573]: ipa-httpd-kdcproxy: INFO KDC proxy enabled Jan 10 08:34:04 hn-dlp systemd[1]: Started The Apache HTTP Server. Jan 10 08:34:04 hn-dlp httpd[3577]: Server configured, listening on: port 443, port 80 Jan 10 08:34:04 hn-dlp systemd[1]: Starting IPA Custodia Service... Jan 10 08:34:05 hn-dlp ipa-custodia[3591]: 2021-01-10 08:34:05 - custodia - Custodia instance <main> Jan 10 08:34:05 hn-dlp ipa-custodia[3591]: 2021-01-10 08:34:05 - server - Serving on Unix socket /run/httpd/ipa-custodia.sock Jan 10 08:34:05 hn-dlp systemd[1]: Started IPA Custodia Service. Jan 10 08:34:06 hn-dlp systemd[1]: Starting PKI Tomcat Server pki-tomcat... Jan 10 08:34:06 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:06.321598113 +0100] - ERR - schema-compat-plugin - warning: no entries set up under ou=sudoers,dc=ipa,dc=tecin,dc=net Jan 10 08:34:06 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:06.362783706 +0100] - ERR - schema-compat-plugin - warning: no entries set up under cn=ng, cn=compat,dc=ipa,dc=tecin,dc=net Jan 10 08:34:08 hn-dlp named-pkcs11[3558]: zone 177.19.172.in-addr.arpa/IN: sending notifies (serial 1610264042) Jan 10 08:34:08 hn-dlp named-pkcs11[3558]: zone 187.19.172.in-addr.arpa/IN: sending notifies (serial 1610264042) Jan 10 08:34:08 hn-dlp named-pkcs11[3558]: zone 195.19.172.in-addr.arpa/IN: sending notifies (serial 1610264042) Jan 10 08:34:08 hn-dlp named-pkcs11[3558]: zone 197.19.172.in-addr.arpa/IN: sending notifies (serial 1610264042) Jan 10 08:34:08 hn-dlp sssd[711]: Keytab successfully retrieved and stored in: /var/lib/sss/keytabs/int.example.local.keytab0Vfy0Q Jan 10 08:34:08 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:08.690270615 +0100] - ERR - schema-compat-plugin - warning: no entries set up under cn=computers, cn=compat,dc=ipa,dc=tecin,dc=net Jan 10 08:34:08 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:34:08.691552993 +0100] - ERR - schema-compat-plugin - Finished plugin initialization. Jan 10 08:34:12 hn-dlp server[3994]: Java virtual machine used: /usr/lib/jvm/jre-openjdk/bin/java Jan 10 08:34:12 hn-dlp server[3994]: classpath used: /usr/share/tomcat/bin/bootstrap.jar:/usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/ant.jar:/usr/share/java/ant-launcher.jar:/usr/lib/jvm/java/lib/tools.jar Jan 10 08:34:12 hn-dlp server[3994]: main class used: org.apache.catalina.startup.Bootstrap Jan 10 08:34:12 hn-dlp server[3994]: flags used: -Dcom.redhat.fips=false Jan 10 08:34:12 hn-dlp server[3994]: options used: -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Djava.security.manager -Djava.security.policy==/var/lib/pki/pki-tomcat/conf/catalina.policy Jan 10 08:34:12 hn-dlp server[3994]: arguments used: start Jan 10 08:34:13 hn-dlp ipa-pki-wait-running[3995]: pki.client: /usr/libexec/ipa/ipa-pki-wait-running:63: The subsystem in PKIConnection.__init__() has been deprecated (https://www.dogtagpki.org/wiki/PKI_10.8_Python_Changes). Jan 10 08:34:13 hn-dlp ipa-pki-wait-running[3995]: ipa-pki-wait-running: Created connection http://hn-dlp.ipa.example.local:8080/ca Jan 10 08:34:13 hn-dlp ipa-pki-wait-running[3995]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Max retries exceeded with url: /ca/admin/ca/getStatus (Caused by NewConnectionError('<urllib3.connection.HTTPConnection object at 0x7f31a810abe0>: Failed to establish a new connection: [Errno 111] Connection refused',)) Jan 10 08:34:14 hn-dlp ipa-pki-wait-running[3995]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Max retries exceeded with url: /ca/admin/ca/getStatus (Caused by NewConnectionError('<urllib3.connection.HTTPConnection object at 0x7f31a810afd0>: Failed to establish a new connection: [Errno 111] Connection refused',)) Jan 10 08:34:15 hn-dlp server[3994]: WARNING: Some of the specified [protocols] are not supported by the SSL engine and have been skipped: [[TLSv1, TLSv1.1]] Jan 10 08:34:16 hn-dlp ipa-pki-wait-running[3995]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 08:34:18 hn-dlp ipa-pki-wait-running[3995]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 08:34:20 hn-dlp ipa-pki-wait-running[3995]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 08:34:22 hn-dlp ipa-pki-wait-running[3995]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 08:34:23 hn-dlp ipa-pki-wait-running[3995]: ipa-pki-wait-running: Success, subsystem ca is running! Jan 10 08:34:23 hn-dlp systemd[1]: Started PKI Tomcat Server pki-tomcat. Jan 10 08:34:23 hn-dlp systemd[1]: Reached target PKI Tomcat Server. Jan 10 08:34:24 hn-dlp systemd[1]: Starting Samba SMB Daemon... Jan 10 08:34:27 hn-dlp smbd[4129]: [2021/01/10 08:34:27.039249, 0] ../../lib/util/become_daemon.c:136(daemon_ready) Jan 10 08:34:27 hn-dlp systemd[1]: Started Samba SMB Daemon. Jan 10 08:34:27 hn-dlp smbd[4129]: daemon_ready: daemon 'smbd' finished starting up and ready to serve connections Jan 10 08:34:27 hn-dlp systemd[1]: Starting Samba Winbind Daemon... Jan 10 08:34:27 hn-dlp winbindd[4138]: [2021/01/10 08:34:27.519233, 0] ../../source3/winbindd/winbindd_cache.c:3205(initialize_winbindd_cache) Jan 10 08:34:27 hn-dlp winbindd[4138]: initialize_winbindd_cache: clearing cache and re-creating with version number 2 Jan 10 08:34:27 hn-dlp winbindd[4138]: [2021/01/10 08:34:27.551194, 0] ../../lib/util/become_daemon.c:136(daemon_ready) Jan 10 08:34:27 hn-dlp winbindd[4138]: daemon_ready: daemon 'winbindd' finished starting up and ready to serve connections Jan 10 08:34:27 hn-dlp systemd[1]: Started Samba Winbind Daemon. Jan 10 08:34:27 hn-dlp systemd[1]: Listening on ipa-otpd socket. Jan 10 08:34:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:34:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 38. Jan 10 08:34:53 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:34:53 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:34:53 hn-dlp systemd[1]: Starting OpenDNSSEC Enforcer daemon... Jan 10 08:34:53 hn-dlp ods-enforcerd[4157]: [engine] running as pid 4157 Jan 10 08:34:53 hn-dlp ods-enforcerd[4157]: [engine] enforcer started Jan 10 08:34:53 hn-dlp ods-enforcerd[4157]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:34:54 hn-dlp ods-enforcerd[4157]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:34:54 hn-dlp ods-enforcerd[4157]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:34:54 hn-dlp ods-enforcerd[4157]: OSSLEVPSymmetricAlgorithm.cpp(512): EVP_DecryptFinal failed (0x00000000): error:2606A074:engine routines:ENGINE_by_id:no such engine Jan 10 08:34:54 hn-dlp ods-enforcerd[4157]: [engine] hsm_session_init(): Incorrect PIN for repository SoftHSM Jan 10 08:34:54 hn-dlp ods-enforcerd[4157]: setup failed: HSM error Jan 10 08:34:54 hn-dlp ods-enforcerd[4157]: [engine] enforcer shutdown Jan 10 08:34:54 hn-dlp ods-enforcerd[4157]: [engine] enforcerd (pid: 4157) stopped with exitcode 3 Jan 10 08:34:54 hn-dlp ods-enforcerd[4156]: [engine] fail to start enforcerd completely Jan 10 08:34:54 hn-dlp ods-enforcerd[4156]: OpenDNSSEC key and signing policy enforcer version 2.1.6 Jan 10 08:34:54 hn-dlp ods-enforcerd[4156]: hsm_session_init(): Incorrect PIN for repository SoftHSM Jan 10 08:34:54 hn-dlp systemd[1]: ods-enforcerd.service: Control process exited, code=exited status=1 Jan 10 08:34:54 hn-dlp systemd[1]: ods-enforcerd.service: Failed with result 'exit-code'. Jan 10 08:34:54 hn-dlp systemd[1]: Failed to start OpenDNSSEC Enforcer daemon. Jan 10 08:34:54 hn-dlp systemd[1]: Stopping Kerberos 5 KDC... Jan 10 08:34:55 hn-dlp systemd[1]: krb5kdc.service: Succeeded. Jan 10 08:34:55 hn-dlp systemd[1]: Stopped Kerberos 5 KDC. Jan 10 08:34:55 hn-dlp systemd[1]: Stopping Kerberos 5 Password-changing and Administration... Jan 10 08:34:55 hn-dlp systemd[1]: kadmin.service: Succeeded. Jan 10 08:34:55 hn-dlp systemd[1]: Stopped Kerberos 5 Password-changing and Administration. Jan 10 08:34:55 hn-dlp systemd[1]: Stopping Berkeley Internet Name Domain (DNS) with native PKCS#11... Jan 10 08:34:55 hn-dlp named-pkcs11[3558]: received control channel command 'stop' Jan 10 08:34:55 hn-dlp named-pkcs11[3558]: shutting down: flushing changes Jan 10 08:34:55 hn-dlp named-pkcs11[3558]: stopping command channel on 127.0.0.1#953 Jan 10 08:34:55 hn-dlp named-pkcs11[3558]: stopping command channel on ::1#953 Jan 10 08:34:55 hn-dlp named-pkcs11[3558]: unloading DynDB instance 'ipa' Jan 10 08:34:55 hn-dlp named-pkcs11[3558]: zone 177.19.172.in-addr.arpa/IN: shutting down Jan 10 08:34:55 hn-dlp named-pkcs11[3558]: zone 187.19.172.in-addr.arpa/IN: shutting down Jan 10 08:34:55 hn-dlp named-pkcs11[3558]: zone 195.19.172.in-addr.arpa/IN: shutting down Jan 10 08:34:55 hn-dlp named-pkcs11[3558]: zone 197.19.172.in-addr.arpa/IN: shutting down Jan 10 08:34:55 hn-dlp named-pkcs11[3558]: zone ipa.example.local/IN: shutting down Jan 10 08:34:55 hn-dlp named-pkcs11[3558]: no longer listening on ::#53 Jan 10 08:34:55 hn-dlp named-pkcs11[3558]: no longer listening on 127.0.0.1#53 Jan 10 08:34:55 hn-dlp named-pkcs11[3558]: no longer listening on 172.19.187.2#53 Jan 10 08:34:56 hn-dlp named-pkcs11[3558]: exiting Jan 10 08:34:56 hn-dlp systemd[1]: named-pkcs11.service: Succeeded. Jan 10 08:34:56 hn-dlp systemd[1]: Stopped Berkeley Internet Name Domain (DNS) with native PKCS#11. Jan 10 08:34:56 hn-dlp systemd[1]: Stopping The Apache HTTP Server... Jan 10 08:34:58 hn-dlp systemd[1]: httpd.service: Succeeded. Jan 10 08:34:58 hn-dlp systemd[1]: Stopped The Apache HTTP Server. Jan 10 08:34:58 hn-dlp systemd[1]: Stopping IPA Custodia Service... Jan 10 08:34:58 hn-dlp systemd[1]: ipa-custodia.service: Succeeded. Jan 10 08:34:58 hn-dlp systemd[1]: Stopped IPA Custodia Service. Jan 10 08:34:58 hn-dlp systemd[1]: Stopped target PKI Tomcat Server. Jan 10 08:34:58 hn-dlp systemd[1]: Stopping PKI Tomcat Server pki-tomcat... Jan 10 08:34:58 hn-dlp systemd[1]: Stopping Samba SMB Daemon... Jan 10 08:34:58 hn-dlp systemd[1]: smb.service: Succeeded. Jan 10 08:34:58 hn-dlp systemd[1]: Stopped Samba SMB Daemon. Jan 10 08:34:58 hn-dlp server[4197]: Java virtual machine used: /usr/lib/jvm/jre-openjdk/bin/java Jan 10 08:34:58 hn-dlp server[4197]: classpath used: /usr/share/tomcat/bin/bootstrap.jar:/usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/ant.jar:/usr/share/java/ant-launcher.jar:/usr/lib/jvm/java/lib/tools.jar Jan 10 08:34:58 hn-dlp server[4197]: main class used: org.apache.catalina.startup.Bootstrap Jan 10 08:34:58 hn-dlp server[4197]: flags used: -Dcom.redhat.fips=false Jan 10 08:34:58 hn-dlp server[4197]: options used: -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager Jan 10 08:34:58 hn-dlp server[4197]: arguments used: stop Jan 10 08:34:58 hn-dlp systemd[1]: Stopping Samba Winbind Daemon... Jan 10 08:35:01 hn-dlp systemd[1]: pki-tomcatd@pki-tomcat.service: Succeeded. Jan 10 08:35:01 hn-dlp systemd[1]: Stopped PKI Tomcat Server pki-tomcat. Jan 10 08:35:02 hn-dlp platform-python[4152]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:35:02 hn-dlp platform-python[4152]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:35:02 hn-dlp platform-python[4152]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:35:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[4152]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 08:35:02 hn-dlp ipa-ods-exporter[4152]: Traceback (most recent call last): Jan 10 08:35:02 hn-dlp ipa-ods-exporter[4152]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 08:35:02 hn-dlp ipa-ods-exporter[4152]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 08:35:02 hn-dlp ipa-ods-exporter[4152]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 08:35:02 hn-dlp ipa-ods-exporter[4152]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 08:35:02 hn-dlp ipa-ods-exporter[4152]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 08:35:02 hn-dlp ipa-ods-exporter[4152]: h = self.p11.import_public_key(**params) Jan 10 08:35:02 hn-dlp ipa-ods-exporter[4152]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 08:35:02 hn-dlp ipa-ods-exporter[4152]: raise DuplicationError("Public key with same ID already exists") Jan 10 08:35:02 hn-dlp ipa-ods-exporter[4152]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 08:35:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:35:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:35:12 hn-dlp winbindd[4138]: [2021/01/10 08:35:12.702978, 0] ../../source3/winbindd/winbindd.c:245(winbindd_sig_term_handler) Jan 10 08:35:12 hn-dlp winbindd[4138]: Got sig[15] terminate (is_parent=1) Jan 10 08:35:12 hn-dlp systemd[1]: winbind.service: Succeeded. Jan 10 08:35:12 hn-dlp systemd[1]: Stopped Samba Winbind Daemon. Jan 10 08:35:12 hn-dlp systemd[1]: ipa-otpd.socket: Succeeded. Jan 10 08:35:12 hn-dlp systemd[1]: Closed ipa-otpd socket. Jan 10 08:35:12 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:35:12 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:35:12 hn-dlp systemd[1]: Stopping 389 Directory Server IPA-TECIN-NET.... Jan 10 08:35:13 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:35:13.041316911 +0100] - INFO - op_thread_cleanup - slapd shutting down - signaling operation threads - op stack size 9 max work q size 4 max work q stack size 4 Jan 10 08:35:13 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:35:13.049164612 +0100] - INFO - slapd_daemon - slapd shutting down - closing down internal subsystems and plugins Jan 10 08:35:14 hn-dlp rsyslogd[1019]: imjournal: journal files changed, reloading... [v8.1911.0-6.el8 try https://www.rsyslog.com/e/0 ] Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: Traceback (most recent call last): Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1078, in error_handler Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: yield Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: '', auth_tokens, server_controls, client_controls) Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 465, in sasl_interactive_bind_s Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: return self._ldap_call(self._l.sasl_interactive_bind_s,who,auth,RequestControlTuples(serverctrls),RequestControlTuples(clientctrls),sasl_flags) Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 329, in _ldap_call Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: reraise(exc_type, exc_value, exc_traceback) Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: File "/usr/lib64/python3.6/site-packages/ldap/compat.py", line 44, in reraise Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: raise exc_value Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 313, in _ldap_call Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: result = func(*args,**kwargs) Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: ldap.SERVER_DOWN: {'desc': "Can't contact LDAP server", 'errno': 111, 'info': 'Connection refused'} Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: During handling of the above exception, another exception occurred: Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: Traceback (most recent call last): Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: File "/usr/libexec/ipa/ipa-ods-exporter", line 689, in <module> Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: ldap.gssapi_bind() Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: '', auth_tokens, server_controls, client_controls) Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: File "/usr/lib64/python3.6/contextlib.py", line 99, in __exit__ Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: self.gen.throw(type, value, traceback) Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1132, in error_handler Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: error=info) Jan 10 08:35:15 hn-dlp ipa-ods-exporter[4229]: ipalib.errors.NetworkError: cannot connect to 'ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket': Connection refused Jan 10 08:35:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:35:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:35:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:36:04 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:36:04.803575045 +0100] - INFO - bdb_pre_close - Waiting for 4 database threads to stop Jan 10 08:36:06 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:36:06.957979587 +0100] - INFO - bdb_pre_close - All database threads now stopped Jan 10 08:36:07 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:36:07.002284679 +0100] - INFO - ldbm_back_instance_set_destructor - Set of instances destroyed Jan 10 08:36:07 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:36:07.009012730 +0100] - INFO - connection_post_shutdown_cleanup - slapd shutting down - freed 4 work q stack objects - freed 9 op stack objects Jan 10 08:36:07 hn-dlp ns-slapd[3487]: [10/Jan/2021:08:36:07.030354002 +0100] - INFO - main - slapd stopped. Jan 10 08:36:07 hn-dlp systemd[1]: dirsrv@IPA-TECIN-NET.service: Succeeded. Jan 10 08:36:07 hn-dlp systemd[1]: Stopped 389 Directory Server IPA-TECIN-NET.. Jan 10 08:36:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:36:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 39. Jan 10 08:36:15 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:36:15 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: Traceback (most recent call last): Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1078, in error_handler Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: yield Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: '', auth_tokens, server_controls, client_controls) Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 465, in sasl_interactive_bind_s Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: return self._ldap_call(self._l.sasl_interactive_bind_s,who,auth,RequestControlTuples(serverctrls),RequestControlTuples(clientctrls),sasl_flags) Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 329, in _ldap_call Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: reraise(exc_type, exc_value, exc_traceback) Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: File "/usr/lib64/python3.6/site-packages/ldap/compat.py", line 44, in reraise Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: raise exc_value Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 313, in _ldap_call Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: result = func(*args,**kwargs) Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: ldap.SERVER_DOWN: {'desc': "Can't contact LDAP server", 'errno': 111, 'info': 'Connection refused'} Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: During handling of the above exception, another exception occurred: Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: Traceback (most recent call last): Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: File "/usr/libexec/ipa/ipa-ods-exporter", line 689, in <module> Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: ldap.gssapi_bind() Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: '', auth_tokens, server_controls, client_controls) Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: File "/usr/lib64/python3.6/contextlib.py", line 99, in __exit__ Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: self.gen.throw(type, value, traceback) Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1132, in error_handler Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: error=info) Jan 10 08:36:18 hn-dlp ipa-ods-exporter[4247]: ipalib.errors.NetworkError: cannot connect to 'ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket': Connection refused Jan 10 08:36:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:36:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:37:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:37:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 40. Jan 10 08:37:18 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:37:18 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: Traceback (most recent call last): Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1078, in error_handler Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: yield Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: '', auth_tokens, server_controls, client_controls) Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 465, in sasl_interactive_bind_s Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: return self._ldap_call(self._l.sasl_interactive_bind_s,who,auth,RequestControlTuples(serverctrls),RequestControlTuples(clientctrls),sasl_flags) Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 329, in _ldap_call Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: reraise(exc_type, exc_value, exc_traceback) Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: File "/usr/lib64/python3.6/site-packages/ldap/compat.py", line 44, in reraise Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: raise exc_value Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 313, in _ldap_call Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: result = func(*args,**kwargs) Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: ldap.SERVER_DOWN: {'desc': "Can't contact LDAP server", 'errno': 111, 'info': 'Connection refused'} Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: During handling of the above exception, another exception occurred: Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: Traceback (most recent call last): Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: File "/usr/libexec/ipa/ipa-ods-exporter", line 689, in <module> Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: ldap.gssapi_bind() Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: '', auth_tokens, server_controls, client_controls) Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: File "/usr/lib64/python3.6/contextlib.py", line 99, in __exit__ Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: self.gen.throw(type, value, traceback) Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1132, in error_handler Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: error=info) Jan 10 08:37:21 hn-dlp ipa-ods-exporter[4254]: ipalib.errors.NetworkError: cannot connect to 'ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket': Connection refused Jan 10 08:37:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:37:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:37:37 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:38:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:38:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 41. Jan 10 08:38:21 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:38:21 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: Traceback (most recent call last): Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1078, in error_handler Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: yield Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: '', auth_tokens, server_controls, client_controls) Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 465, in sasl_interactive_bind_s Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: return self._ldap_call(self._l.sasl_interactive_bind_s,who,auth,RequestControlTuples(serverctrls),RequestControlTuples(clientctrls),sasl_flags) Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 329, in _ldap_call Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: reraise(exc_type, exc_value, exc_traceback) Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: File "/usr/lib64/python3.6/site-packages/ldap/compat.py", line 44, in reraise Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: raise exc_value Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: File "/usr/lib64/python3.6/site-packages/ldap/ldapobject.py", line 313, in _ldap_call Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: result = func(*args,**kwargs) Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: ldap.SERVER_DOWN: {'desc': "Can't contact LDAP server", 'errno': 111, 'info': 'Connection refused'} Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: During handling of the above exception, another exception occurred: Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: Traceback (most recent call last): Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: File "/usr/libexec/ipa/ipa-ods-exporter", line 689, in <module> Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: ldap.gssapi_bind() Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1250, in gssapi_bind Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: '', auth_tokens, server_controls, client_controls) Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: File "/usr/lib64/python3.6/contextlib.py", line 99, in __exit__ Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: self.gen.throw(type, value, traceback) Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: File "/usr/lib/python3.6/site-packages/ipapython/ipaldap.py", line 1132, in error_handler Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: error=info) Jan 10 08:38:24 hn-dlp ipa-ods-exporter[4263]: ipalib.errors.NetworkError: cannot connect to 'ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket': Connection refused Jan 10 08:38:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:38:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:39:07 hn-dlp systemd[1]: Starting 389 Directory Server IPA-TECIN-NET.... Jan 10 08:39:08 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:08.280760828 +0100] - INFO - slapd_extract_cert - CA CERT NAME: IPA.example.local IPA CA Jan 10 08:39:08 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:08.282453987 +0100] - INFO - slapd_extract_cert - CA CERT NAME: DC=tecin,DC=net,E=info@example.local,CN=TecIn-CA Jan 10 08:39:08 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:08.283952532 +0100] - WARN - Security Initialization - SSL alert: Sending pin request to SVRCore. You may need to run systemd-tty-ask-password-agent to provide the password. Jan 10 08:39:08 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:08.535277083 +0100] - INFO - slapd_extract_cert - SERVER CERT NAME: Server-Cert Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.068107525 +0100] - INFO - Security Initialization - SSL info: Enabling default cipher set. Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.069170376 +0100] - INFO - Security Initialization - SSL info: Configured NSS Ciphers Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.069665559 +0100] - INFO - Security Initialization - SSL info: #011TLS_AES_128_GCM_SHA256: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.070304873 +0100] - INFO - Security Initialization - SSL info: #011TLS_CHACHA20_POLY1305_SHA256: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.070957549 +0100] - INFO - Security Initialization - SSL info: #011TLS_AES_256_GCM_SHA384: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.071454072 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.072124529 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.072757753 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.073416864 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.074344539 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.074960414 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.075496542 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.076044799 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.076508157 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.077060829 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.077516376 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.078027941 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.078624423 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.079376655 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.080081385 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.080609827 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_128_CBC_SHA: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.081292739 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.081864627 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_256_CBC_SHA: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.082348817 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_256_CBC_SHA256: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.082803785 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.083262773 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.083875715 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_128_CBC_SHA: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.084526589 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.085205641 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_256_CBC_SHA: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.085963897 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_256_CBC_SHA256: enabled Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.699548471 +0100] - INFO - Security Initialization - slapd_ssl_init2 - Configured SSL version range: min: TLS1.2, max: TLS1.3 Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.700340534 +0100] - INFO - Security Initialization - slapd_ssl_init2 - NSS adjusted SSL version range: min: TLS1.2, max: TLS1.3 Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.707846870 +0100] - INFO - main - 389-Directory/1.4.3.8 B2020.357.1921 starting up Jan 10 08:39:09 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:09.708449867 +0100] - INFO - main - Setting the maximum file descriptor limit to: 262144 Jan 10 08:39:10 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:10.797443781 +0100] - INFO - PBKDF2_SHA256 - Based on CPU performance, chose 2048 rounds Jan 10 08:39:10 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:10.801878040 +0100] - INFO - ldbm_instance_config_cachememsize_set - force a minimal value 512000 Jan 10 08:39:10 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:10.811830277 +0100] - INFO - ldbm_instance_config_cachememsize_set - force a minimal value 512000 Jan 10 08:39:10 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:10.818312914 +0100] - INFO - ldbm_instance_config_cachememsize_set - force a minimal value 512000 Jan 10 08:39:10 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:10.823844485 +0100] - NOTICE - ldbm_back_start - found 1343712k physical memory Jan 10 08:39:10 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:10.824505691 +0100] - NOTICE - ldbm_back_start - found 875380k available Jan 10 08:39:10 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:10.825177583 +0100] - NOTICE - ldbm_back_start - cache autosizing: db cache: 33592k Jan 10 08:39:10 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:10.831557452 +0100] - NOTICE - ldbm_back_start - cache autosizing: userRoot entry cache (3 total): 65536k Jan 10 08:39:10 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:10.835761293 +0100] - NOTICE - ldbm_back_start - cache autosizing: userRoot dn cache (3 total): 65536k Jan 10 08:39:10 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:10.839629017 +0100] - NOTICE - ldbm_back_start - cache autosizing: ipaca entry cache (3 total): 65536k Jan 10 08:39:10 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:10.843744839 +0100] - NOTICE - ldbm_back_start - cache autosizing: ipaca dn cache (3 total): 65536k Jan 10 08:39:10 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:10.847495187 +0100] - NOTICE - ldbm_back_start - cache autosizing: changelog entry cache (3 total): 65536k Jan 10 08:39:10 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:10.851553843 +0100] - NOTICE - ldbm_back_start - cache autosizing: changelog dn cache (3 total): 65536k Jan 10 08:39:10 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:10.855609948 +0100] - NOTICE - ldbm_back_start - total cache size: 430172405 B; Jan 10 08:39:11 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:11.154358508 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher AES Jan 10 08:39:11 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:11.155282077 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 08:39:11 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:11.439341983 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher 3DES Jan 10 08:39:11 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:11.440271735 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 08:39:11 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:11.443789464 +0100] - ERR - attrcrypt_init - All prepared ciphers are not available. Please disable attribute encryption. Jan 10 08:39:11 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:11.726888211 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher AES Jan 10 08:39:11 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:11.727936654 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 08:39:11 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:11.985552200 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher 3DES Jan 10 08:39:11 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:11.986733225 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 08:39:11 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:11.990761537 +0100] - ERR - attrcrypt_init - All prepared ciphers are not available. Please disable attribute encryption. Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.587259027 +0100] - ERR - schema-compat-plugin - scheduled schema-compat-plugin tree scan in about 5 seconds after the server startup! Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.613040928 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=groups,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.614052390 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=computers,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.615019298 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=ng,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.620302268 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target ou=sudoers,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.624186469 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=users,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.628386746 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.632271237 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.636348225 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.640303142 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.643828665 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.644817245 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.645692888 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.646542294 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.647566234 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.650311541 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.651375736 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.659102863 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.660303888 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.763301547 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=automember rebuild membership,cn=tasks,cn=config does not exist Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.768518035 +0100] - ERR - cos-plugin - cos_dn_defs_cb - Skipping CoS Definition cn=Password Policy,cn=accounts,dc=ipa,dc=tecin,dc=net--no CoS Templates found, which should be added before the CoS Definition. Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.863607030 +0100] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/hn-dlp.ipa.example.local@IPA.example.local] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC for requested realm) Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.864950499 +0100] - INFO - slapd_daemon - slapd started. Listening on All Interfaces port 389 for LDAP requests Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.866490386 +0100] - INFO - slapd_daemon - Listening on All Interfaces port 636 for LDAPS requests Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.871581912 +0100] - INFO - slapd_daemon - Listening on /var/run/slapd-IPA-TECIN-NET.socket for LDAPI requests Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.875639901 +0100] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/hn-dlp.ipa.example.local@IPA.example.local] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC for requested realm) Jan 10 08:39:12 hn-dlp systemd[1]: Started 389 Directory Server IPA-TECIN-NET.. Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.882885065 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=meToha-dlp.ipa.example.local" (ha-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.885347066 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=meTonf-dlp.ipa.example.local" (nf-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.887608891 +0100] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/hn-dlp.ipa.example.local@IPA.example.local] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC for requested realm) Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.892167312 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=caToha-dlp.ipa.example.local" (ha-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.895483069 +0100] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/hn-dlp.ipa.example.local@IPA.example.local] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC for requested realm) Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.900022354 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=caTonf-dlp.ipa.example.local" (nf-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 08:39:12 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:12.913404868 +0100] - ERR - schema-compat-plugin - schema-compat-plugin tree scan will start in about 5 seconds! Jan 10 08:39:13 hn-dlp systemd[1]: Starting Kerberos 5 KDC... Jan 10 08:39:13 hn-dlp systemd[1]: krb5kdc.service: Can't open PID file /var/run/krb5kdc.pid (yet?) after start: No such file or directory Jan 10 08:39:13 hn-dlp systemd[1]: Started Kerberos 5 KDC. Jan 10 08:39:13 hn-dlp systemd[1]: Starting Kerberos 5 Password-changing and Administration... Jan 10 08:39:13 hn-dlp systemd[1]: Started Kerberos 5 Password-changing and Administration. Jan 10 08:39:13 hn-dlp systemd[1]: Starting Generate rndc key for BIND (DNS)... Jan 10 08:39:13 hn-dlp systemd[1]: named-setup-rndc.service: Succeeded. Jan 10 08:39:13 hn-dlp systemd[1]: Started Generate rndc key for BIND (DNS). Jan 10 08:39:13 hn-dlp systemd[1]: Starting Berkeley Internet Name Domain (DNS) with native PKCS#11... Jan 10 08:39:13 hn-dlp bash[4349]: zone localhost.localdomain/IN: loaded serial 0 Jan 10 08:39:13 hn-dlp bash[4349]: zone localhost/IN: loaded serial 0 Jan 10 08:39:13 hn-dlp bash[4349]: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 0 Jan 10 08:39:13 hn-dlp bash[4349]: zone 1.0.0.127.in-addr.arpa/IN: loaded serial 0 Jan 10 08:39:13 hn-dlp bash[4349]: zone 0.in-addr.arpa/IN: loaded serial 0 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: starting BIND 9.11.20-RedHat-9.11.20-5.el8 (Extended Support Version) <id:f3d1d66> Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: running on Linux x86_64 4.18.0-240.1.1.el8_3.x86_64 #1 SMP Thu Nov 19 17:20:08 UTC 2020 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: built with '--build=x86_64-redhat-linux-gnu' '--host=x86_64-redhat-linux-gnu' '--program-prefix=' '--disable-dependency-tracking' '--prefix=/usr' '--exec-prefix=/usr' '--bindir=/usr/bin' '--sbindir=/usr/sbin' '--sysconfdir=/etc' '--datadir=/usr/share' '--includedir=/usr/include' '--libdir=/usr/lib64' '--libexecdir=/usr/libexec' '--sharedstatedir=/var/lib' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--with-python=/usr/libexec/platform-python' '--with-libtool' '--localstatedir=/var' '--enable-threads' '--enable-ipv6' '--enable-filter-aaaa' '--with-pic' '--disable-static' '--includedir=/usr/include/bind9' '--with-tuning=large' '--with-libidn2' '--enable-openssl-hash' '--with-geoip2' '--enable-native-pkcs11' '--with-pkcs11=/usr/lib64/pkcs11/libsofthsm2.so' '--with-dlopen=yes' '--with-dlz-ldap=yes' '--with-dlz-postgres=yes' '--with-dlz-mysql=yes' '--with-dlz-filesystem=yes' '--with-dlz-bdb=yes' '--with-gssapi=yes' '--disable-isc-spnego' '--with-lmdb=no' '--with-cmocka' '--enable-fixed-rrset' '--with-docbook-xsl=/usr/share/sgml/docbook/xsl-stylesheets' '--enable-full-report' 'build_alias=x86_64-redhat-linux-gnu' 'host_alias=x86_64-redhat-linux-gnu' 'CFLAGS= -O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection' 'LDFLAGS=-Wl,-z,relro -Wl,-z,now -specs=/usr/lib/rpm/redhat/redhat-hardened-ld' 'CPPFLAGS= -DDIG_SIGCHASE' 'PKG_CONFIG_PATH=:/usr/lib64/pkgconfig:/usr/share/pkgconfig' Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: running as: named-pkcs11 -u named -c /etc/named.conf Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: compiled by GCC 8.3.1 20191121 (Red Hat 8.3.1-5) Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: compiled with libxml2 version: 2.9.7 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: linked to libxml2 version: 20907 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: compiled with zlib version: 1.2.11 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: linked to zlib version: 1.2.11 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: threads support is enabled Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: ---------------------------------------------------- Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: BIND 9 is maintained by Internet Systems Consortium, Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: Inc. (ISC), a non-profit 501(c)(3) public-benefit Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: corporation. Support and training for BIND 9 are Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: available at https://www.isc.org/support Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: ---------------------------------------------------- Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: adjusted limit on open files from 262144 to 1048576 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: found 4 CPUs, using 4 worker threads Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: using 3 UDP listeners per interface Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: using up to 21000 sockets Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: loading configuration from '/etc/named.conf' Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: unable to open '/etc/bind.keys'; using built-in keys instead Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: looking for GeoIP2 databases in '/usr/share/GeoIP' Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-Country.mmdb' Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-City.mmdb' Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: using default UDP/IPv4 port range: [32768, 60999] Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: using default UDP/IPv6 port range: [32768, 60999] Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: listening on IPv6 interfaces, port 53 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: listening on IPv4 interface lo, 127.0.0.1#53 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: listening on IPv4 interface ens18, 172.19.187.2#53 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: generating session key for dynamic DNS Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: sizing zone task pool based on 6 zones Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: none:104: 'max-cache-size 90%' - setting to 1180MB (out of 1312MB) Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: set up managed keys zone for view _default, file '/var/named/dynamic/managed-keys.bind' Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: loading DynDB instance 'ipa' driver '/usr/lib64/bind/ldap.so' Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: bind-dyndb-ldap version 11.3 compiled at 16:06:42 Sep 1 2020, compiler 8.3.1 20191121 (Red Hat 8.3.1-5) Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 10.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 16.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 17.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 18.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 19.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 20.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 21.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 22.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 23.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 24.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 25.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 26.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 27.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 28.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 29.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 30.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 31.172.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 168.192.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 64.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 65.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 66.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 67.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 68.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 69.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 70.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 71.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 72.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 73.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 74.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 75.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 76.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 77.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 78.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 79.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 80.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 81.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 82.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 83.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 84.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 85.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 86.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 87.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 88.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 89.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 90.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 91.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 92.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 93.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 94.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 95.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 96.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 97.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 98.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 99.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 100.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 101.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 102.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 103.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 104.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 105.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 106.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 107.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 108.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 109.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 110.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 111.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 112.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 113.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 114.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 115.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 116.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 117.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 118.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 119.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 120.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 121.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 122.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 123.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 124.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 125.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 126.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 127.100.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 127.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 254.169.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 2.0.192.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 100.51.198.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 113.0.203.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 255.255.255.255.IN-ADDR.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: D.F.IP6.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 8.E.F.IP6.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 9.E.F.IP6.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: A.E.F.IP6.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: B.E.F.IP6.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: 8.B.D.0.1.0.0.2.IP6.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: EMPTY.AS112.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: automatic empty zone: HOME.ARPA Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: none:104: 'max-cache-size 90%' - setting to 1180MB (out of 1312MB) Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: configuring command channel from '/etc/rndc.key' Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: command channel listening on 127.0.0.1#953 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: configuring command channel from '/etc/rndc.key' Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: command channel listening on ::1#953 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: managed-keys-zone: journal file is out of date: removing journal file Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: managed-keys-zone: loaded serial 228 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: zone 0.in-addr.arpa/IN: loaded serial 0 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: shutting down automatic empty zones to enable forwarding for domain '.' Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: zone 118.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: zone EMPTY.AS112.ARPA/IN: shutting down Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: zone 1.0.0.127.in-addr.arpa/IN: loaded serial 0 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 0 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: zone localhost.localdomain/IN: loaded serial 0 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: zone localhost/IN: loaded serial 0 Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: all zones loaded Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: running Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: LDAP configuration for instance 'ipa' synchronized Jan 10 08:39:13 hn-dlp systemd[1]: Started Berkeley Internet Name Domain (DNS) with native PKCS#11. Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: LDAP data for instance 'ipa' are being synchronized, please ignore message 'all zones loaded' Jan 10 08:39:13 hn-dlp named-pkcs11[4353]: managed-keys-zone: Key 20326 for zone . acceptance timer complete: key now trusted Jan 10 08:39:13 hn-dlp systemd[1]: Starting One-time temporary TLS key generation for httpd.service... Jan 10 08:39:13 hn-dlp systemd[1]: httpd-init.service: Succeeded. Jan 10 08:39:13 hn-dlp systemd[1]: Started One-time temporary TLS key generation for httpd.service. Jan 10 08:39:13 hn-dlp systemd[1]: Starting The Apache HTTP Server... Jan 10 08:39:14 hn-dlp named-pkcs11[4353]: forward zone 'int.example.local': loaded Jan 10 08:39:14 hn-dlp named-pkcs11[4353]: forward zone 'srv.example.local': loaded Jan 10 08:39:14 hn-dlp named-pkcs11[4353]: zone 177.19.172.in-addr.arpa/IN: loaded serial 1610264354 Jan 10 08:39:14 hn-dlp named-pkcs11[4353]: zone 187.19.172.in-addr.arpa/IN: loaded serial 1610264354 Jan 10 08:39:14 hn-dlp named-pkcs11[4353]: zone 195.19.172.in-addr.arpa/IN: loaded serial 1610264354 Jan 10 08:39:14 hn-dlp named-pkcs11[4353]: zone 197.19.172.in-addr.arpa/IN: loaded serial 1610264354 Jan 10 08:39:14 hn-dlp named-pkcs11[4353]: zone ipa.example.local/IN: loaded serial 1610264354 Jan 10 08:39:14 hn-dlp named-pkcs11[4353]: 5 master zones from LDAP instance 'ipa' loaded (5 zones defined, 0 inactive, 0 failed to load) Jan 10 08:39:14 hn-dlp named-pkcs11[4353]: zone 177.19.172.in-addr.arpa/IN: sending notifies (serial 1610264354) Jan 10 08:39:14 hn-dlp named-pkcs11[4353]: zone 187.19.172.in-addr.arpa/IN: sending notifies (serial 1610264354) Jan 10 08:39:14 hn-dlp named-pkcs11[4353]: zone 195.19.172.in-addr.arpa/IN: sending notifies (serial 1610264354) Jan 10 08:39:14 hn-dlp named-pkcs11[4353]: zone ipa.example.local/IN: sending notifies (serial 1610264354) Jan 10 08:39:14 hn-dlp named-pkcs11[4353]: zone 197.19.172.in-addr.arpa/IN: sending notifies (serial 1610264354) Jan 10 08:39:14 hn-dlp ipa-httpd-kdcproxy[4368]: ipa: INFO: KDC proxy enabled Jan 10 08:39:14 hn-dlp ipa-httpd-kdcproxy[4368]: ipa-httpd-kdcproxy: INFO KDC proxy enabled Jan 10 08:39:14 hn-dlp systemd[1]: Started The Apache HTTP Server. Jan 10 08:39:14 hn-dlp httpd[4372]: Server configured, listening on: port 443, port 80 Jan 10 08:39:14 hn-dlp systemd[1]: Starting IPA Custodia Service... Jan 10 08:39:15 hn-dlp ipa-custodia[4390]: 2021-01-10 08:39:15 - custodia - Custodia instance <main> Jan 10 08:39:16 hn-dlp ipa-custodia[4390]: 2021-01-10 08:39:16 - server - Serving on Unix socket /run/httpd/ipa-custodia.sock Jan 10 08:39:16 hn-dlp systemd[1]: Started IPA Custodia Service. Jan 10 08:39:16 hn-dlp systemd[1]: Starting PKI Tomcat Server pki-tomcat... Jan 10 08:39:17 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:17.927135662 +0100] - ERR - schema-compat-plugin - warning: no entries set up under ou=sudoers,dc=ipa,dc=tecin,dc=net Jan 10 08:39:17 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:17.948792047 +0100] - ERR - schema-compat-plugin - warning: no entries set up under cn=ng, cn=compat,dc=ipa,dc=tecin,dc=net Jan 10 08:39:18 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:18.795743551 +0100] - ERR - schema-compat-plugin - warning: no entries set up under cn=computers, cn=compat,dc=ipa,dc=tecin,dc=net Jan 10 08:39:18 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:39:18.796708416 +0100] - ERR - schema-compat-plugin - Finished plugin initialization. Jan 10 08:39:19 hn-dlp named-pkcs11[4353]: zone 177.19.172.in-addr.arpa/IN: sending notifies (serial 1610264354) Jan 10 08:39:19 hn-dlp named-pkcs11[4353]: zone 187.19.172.in-addr.arpa/IN: sending notifies (serial 1610264354) Jan 10 08:39:19 hn-dlp named-pkcs11[4353]: zone 195.19.172.in-addr.arpa/IN: sending notifies (serial 1610264354) Jan 10 08:39:19 hn-dlp named-pkcs11[4353]: zone ipa.example.local/IN: sending notifies (serial 1610264354) Jan 10 08:39:19 hn-dlp named-pkcs11[4353]: zone 197.19.172.in-addr.arpa/IN: sending notifies (serial 1610264354) Jan 10 08:39:22 hn-dlp server[4786]: Java virtual machine used: /usr/lib/jvm/jre-openjdk/bin/java Jan 10 08:39:22 hn-dlp server[4786]: classpath used: /usr/share/tomcat/bin/bootstrap.jar:/usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/ant.jar:/usr/share/java/ant-launcher.jar:/usr/lib/jvm/java/lib/tools.jar Jan 10 08:39:22 hn-dlp server[4786]: main class used: org.apache.catalina.startup.Bootstrap Jan 10 08:39:22 hn-dlp server[4786]: flags used: -Dcom.redhat.fips=false Jan 10 08:39:22 hn-dlp server[4786]: options used: -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Djava.security.manager -Djava.security.policy==/var/lib/pki/pki-tomcat/conf/catalina.policy Jan 10 08:39:22 hn-dlp server[4786]: arguments used: start Jan 10 08:39:22 hn-dlp ipa-pki-wait-running[4787]: pki.client: /usr/libexec/ipa/ipa-pki-wait-running:63: The subsystem in PKIConnection.__init__() has been deprecated (https://www.dogtagpki.org/wiki/PKI_10.8_Python_Changes). Jan 10 08:39:22 hn-dlp ipa-pki-wait-running[4787]: ipa-pki-wait-running: Created connection http://hn-dlp.ipa.example.local:8080/ca Jan 10 08:39:22 hn-dlp ipa-pki-wait-running[4787]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Max retries exceeded with url: /ca/admin/ca/getStatus (Caused by NewConnectionError('<urllib3.connection.HTTPConnection object at 0x7fba67e9fbe0>: Failed to establish a new connection: [Errno 111] Connection refused',)) Jan 10 08:39:23 hn-dlp ipa-pki-wait-running[4787]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Max retries exceeded with url: /ca/admin/ca/getStatus (Caused by NewConnectionError('<urllib3.connection.HTTPConnection object at 0x7fba67e9ffd0>: Failed to establish a new connection: [Errno 111] Connection refused',)) Jan 10 08:39:24 hn-dlp server[4786]: WARNING: Some of the specified [protocols] are not supported by the SSL engine and have been skipped: [[TLSv1, TLSv1.1]] Jan 10 08:39:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:39:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 42. Jan 10 08:39:24 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:39:24 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:39:25 hn-dlp ipa-pki-wait-running[4787]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 08:39:27 hn-dlp ipa-pki-wait-running[4787]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 08:39:29 hn-dlp ipa-pki-wait-running[4787]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 08:39:31 hn-dlp ipa-pki-wait-running[4787]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 08:39:32 hn-dlp platform-python[4804]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:39:32 hn-dlp platform-python[4804]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:39:32 hn-dlp platform-python[4804]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:39:33 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[4804]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 08:39:33 hn-dlp ipa-ods-exporter[4804]: Traceback (most recent call last): Jan 10 08:39:33 hn-dlp ipa-ods-exporter[4804]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 08:39:33 hn-dlp ipa-ods-exporter[4804]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 08:39:33 hn-dlp ipa-ods-exporter[4804]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 08:39:33 hn-dlp ipa-ods-exporter[4804]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 08:39:33 hn-dlp ipa-ods-exporter[4804]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 08:39:33 hn-dlp ipa-ods-exporter[4804]: h = self.p11.import_public_key(**params) Jan 10 08:39:33 hn-dlp ipa-ods-exporter[4804]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 08:39:33 hn-dlp ipa-ods-exporter[4804]: raise DuplicationError("Public key with same ID already exists") Jan 10 08:39:33 hn-dlp ipa-ods-exporter[4804]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 08:39:33 hn-dlp ipa-pki-wait-running[4787]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 08:39:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:39:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:39:35 hn-dlp ipa-pki-wait-running[4787]: ipa-pki-wait-running: Success, subsystem ca is running! Jan 10 08:39:36 hn-dlp systemd[1]: Started PKI Tomcat Server pki-tomcat. Jan 10 08:39:36 hn-dlp systemd[1]: Reached target PKI Tomcat Server. Jan 10 08:39:36 hn-dlp systemd[1]: Starting Samba SMB Daemon... Jan 10 08:39:37 hn-dlp smbd[4930]: [2021/01/10 08:39:37.942127, 0] ../../lib/util/become_daemon.c:136(daemon_ready) Jan 10 08:39:37 hn-dlp smbd[4930]: daemon_ready: daemon 'smbd' finished starting up and ready to serve connections Jan 10 08:39:37 hn-dlp systemd[1]: Started Samba SMB Daemon. Jan 10 08:39:37 hn-dlp systemd[1]: Starting Samba Winbind Daemon... Jan 10 08:39:38 hn-dlp winbindd[4939]: [2021/01/10 08:39:38.179506, 0] ../../source3/winbindd/winbindd_cache.c:3205(initialize_winbindd_cache) Jan 10 08:39:38 hn-dlp winbindd[4939]: initialize_winbindd_cache: clearing cache and re-creating with version number 2 Jan 10 08:39:38 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:39:38 hn-dlp winbindd[4939]: [2021/01/10 08:39:38.206531, 0] ../../lib/util/become_daemon.c:136(daemon_ready) Jan 10 08:39:38 hn-dlp winbindd[4939]: daemon_ready: daemon 'winbindd' finished starting up and ready to serve connections Jan 10 08:39:38 hn-dlp systemd[1]: Started Samba Winbind Daemon. Jan 10 08:39:38 hn-dlp systemd[1]: Listening on ipa-otpd socket. Jan 10 08:40:23 hn-dlp winbindd[4939]: [2021/01/10 08:40:23.938218, 0] ../../source3/winbindd/wb_lookupsids.c:663(wb_lookupsids_recv) Jan 10 08:40:23 hn-dlp winbindd[4939]: res_names->count = 0, expected 1 Jan 10 08:40:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:40:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 43. Jan 10 08:40:34 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:40:34 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:40:34 hn-dlp systemd[1]: Starting OpenDNSSEC Enforcer daemon... Jan 10 08:40:34 hn-dlp ods-enforcerd[4969]: [engine] running as pid 4969 Jan 10 08:40:34 hn-dlp ods-enforcerd[4969]: [engine] enforcer started Jan 10 08:40:34 hn-dlp ods-enforcerd[4969]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:40:35 hn-dlp ods-enforcerd[4969]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:40:35 hn-dlp ods-enforcerd[4969]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:40:35 hn-dlp ods-enforcerd[4969]: OSSLEVPSymmetricAlgorithm.cpp(512): EVP_DecryptFinal failed (0x00000000): error:2606A074:engine routines:ENGINE_by_id:no such engine Jan 10 08:40:35 hn-dlp ods-enforcerd[4969]: [engine] hsm_session_init(): Incorrect PIN for repository SoftHSM Jan 10 08:40:35 hn-dlp ods-enforcerd[4969]: setup failed: HSM error Jan 10 08:40:35 hn-dlp ods-enforcerd[4969]: [engine] enforcer shutdown Jan 10 08:40:35 hn-dlp ods-enforcerd[4969]: [engine] enforcerd (pid: 4969) stopped with exitcode 3 Jan 10 08:40:35 hn-dlp ods-enforcerd[4968]: [engine] fail to start enforcerd completely Jan 10 08:40:35 hn-dlp ods-enforcerd[4968]: OpenDNSSEC key and signing policy enforcer version 2.1.6 Jan 10 08:40:35 hn-dlp ods-enforcerd[4968]: hsm_session_init(): Incorrect PIN for repository SoftHSM Jan 10 08:40:35 hn-dlp systemd[1]: ods-enforcerd.service: Control process exited, code=exited status=1 Jan 10 08:40:35 hn-dlp systemd[1]: ods-enforcerd.service: Failed with result 'exit-code'. Jan 10 08:40:35 hn-dlp systemd[1]: Failed to start OpenDNSSEC Enforcer daemon. Jan 10 08:40:35 hn-dlp systemd[1]: Started IPA key daemon. Jan 10 08:40:41 hn-dlp platform-python[4964]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: ipa-dnskeysyncd: INFO LDAP bind... Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: ipa-dnskeysyncd: INFO Commencing sync process Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-eeae1a850283edc8a00566c3dee263f0,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c04eba886f71eaf6942e4187a168530d,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-795ec7e363b4e831c99bc7751b006b8e,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-b16ee269a69c62ab190b78039c574e4b,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c5b715f14457ccb40f60e224b2220d7f,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-6e817263927b3519a7b5757e90ba5cfc,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100539Z-49de8f2954963b5779491cdacc9232c5,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-3e7a2e5aaa81fd5f1608f7824dd42b8e,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100552Z-2ff98d67ad4fd9c22202c132ec0d4141,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100556Z-708bc11ade0ce1fe2b4b061e80cc0035,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: ipaserver.dnssec.keysyncer: INFO Initial LDAP dump is done, sychronizing with ODS and BIND Jan 10 08:40:42 hn-dlp platform-python[4964]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:40:42 hn-dlp platform-python[4964]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: Traceback (most recent call last): Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: File "/usr/libexec/ipa/ipa-dnskeysyncd", line 116, in <module> Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: while ldap_connection.syncrepl_poll(all=1, msgid=ldap_search): Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: File "/usr/lib64/python3.6/site-packages/ldap/syncrepl.py", line 457, in syncrepl_poll Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: self.syncrepl_refreshdone() Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/keysyncer.py", line 125, in syncrepl_refreshdone Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: self.ods_sync() Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/keysyncer.py", line 183, in ods_sync Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: self.odsmgr.sync() Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/odsmgr.py", line 221, in sync Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: zl_ods = self.get_ods_zonelist() Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/odsmgr.py", line 143, in get_ods_zonelist Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: stdout = self.ksmutil(['zonelist', 'export']) Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/odsmgr.py", line 139, in ksmutil Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: result = tasks.run_ods_manager(params, capture_output=True) Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/_ods21.py", line 115, in run_ods_manager Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: return ipautil.run(cmd, **kwargs) Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: File "/usr/lib/python3.6/site-packages/ipapython/ipautil.py", line 598, in run Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: p.returncode, arg_string, output_log, error_log Jan 10 08:40:42 hn-dlp ipa-dnskeysyncd[4973]: ipapython.ipautil.CalledProcessError: CalledProcessError(Command ['/usr/sbin/ods-enforcer', 'zonelist', 'export'] returned non-zero exit status 201: 'Unable to connect to engine. connect() failed: Connection refused ("/var/run/opendnssec/enforcer.sock")\n') Jan 10 08:40:42 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[4964]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6', '0x699c52466073aba4c50cfb80a2328204'} Jan 10 08:40:42 hn-dlp ipa-ods-exporter[4964]: Traceback (most recent call last): Jan 10 08:40:42 hn-dlp ipa-ods-exporter[4964]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 08:40:42 hn-dlp ipa-ods-exporter[4964]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 08:40:42 hn-dlp ipa-ods-exporter[4964]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 08:40:42 hn-dlp ipa-ods-exporter[4964]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 08:40:42 hn-dlp ipa-ods-exporter[4964]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 08:40:42 hn-dlp ipa-ods-exporter[4964]: h = self.p11.import_public_key(**params) Jan 10 08:40:42 hn-dlp ipa-ods-exporter[4964]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 08:40:42 hn-dlp ipa-ods-exporter[4964]: raise DuplicationError("Public key with same ID already exists") Jan 10 08:40:42 hn-dlp ipa-ods-exporter[4964]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 08:40:42 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:40:42 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Failed with result 'exit-code'. Jan 10 08:40:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:40:42 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:41:12 hn-dlp named-pkcs11[4353]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 08:41:12 hn-dlp named-pkcs11[4353]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:41:16 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:41:16.202159867 +0100] - INFO - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=meTonf-dlp.ipa.example.local" (nf-dlp:389): Replication bind with GSSAPI auth resumed Jan 10 08:41:38 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:41:42 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:41:42 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Scheduled restart job, restart counter is at 1. Jan 10 08:41:42 hn-dlp systemd[1]: Stopped IPA key daemon. Jan 10 08:41:42 hn-dlp systemd[1]: Started IPA key daemon. Jan 10 08:41:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:41:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 44. Jan 10 08:41:43 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:41:43 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:41:46 hn-dlp platform-python[4993]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:41:46 hn-dlp platform-python[4993]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:41:46 hn-dlp platform-python[4993]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:41:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[4993]: new replica keys in LDAP: {'0x699c52466073aba4c50cfb80a2328204', '0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: ipa-dnskeysyncd: INFO LDAP bind... Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: ipa-dnskeysyncd: INFO Commencing sync process Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-eeae1a850283edc8a00566c3dee263f0,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c04eba886f71eaf6942e4187a168530d,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-795ec7e363b4e831c99bc7751b006b8e,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-b16ee269a69c62ab190b78039c574e4b,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c5b715f14457ccb40f60e224b2220d7f,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-6e817263927b3519a7b5757e90ba5cfc,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100539Z-49de8f2954963b5779491cdacc9232c5,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-3e7a2e5aaa81fd5f1608f7824dd42b8e,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100552Z-2ff98d67ad4fd9c22202c132ec0d4141,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100556Z-708bc11ade0ce1fe2b4b061e80cc0035,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: ipaserver.dnssec.keysyncer: INFO Initial LDAP dump is done, sychronizing with ODS and BIND Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: Traceback (most recent call last): Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: File "/usr/libexec/ipa/ipa-dnskeysyncd", line 116, in <module> Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: while ldap_connection.syncrepl_poll(all=1, msgid=ldap_search): Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: File "/usr/lib64/python3.6/site-packages/ldap/syncrepl.py", line 457, in syncrepl_poll Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: self.syncrepl_refreshdone() Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/keysyncer.py", line 125, in syncrepl_refreshdone Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: self.ods_sync() Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/keysyncer.py", line 183, in ods_sync Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: self.odsmgr.sync() Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/odsmgr.py", line 221, in sync Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: zl_ods = self.get_ods_zonelist() Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/odsmgr.py", line 143, in get_ods_zonelist Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: stdout = self.ksmutil(['zonelist', 'export']) Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/odsmgr.py", line 139, in ksmutil Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: result = tasks.run_ods_manager(params, capture_output=True) Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/_ods21.py", line 115, in run_ods_manager Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: return ipautil.run(cmd, **kwargs) Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: File "/usr/lib/python3.6/site-packages/ipapython/ipautil.py", line 598, in run Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: p.returncode, arg_string, output_log, error_log Jan 10 08:41:46 hn-dlp ipa-dnskeysyncd[4992]: ipapython.ipautil.CalledProcessError: CalledProcessError(Command ['/usr/sbin/ods-enforcer', 'zonelist', 'export'] returned non-zero exit status 201: 'Unable to connect to engine. connect() failed: Connection refused ("/var/run/opendnssec/enforcer.sock")\n') Jan 10 08:41:46 hn-dlp ipa-ods-exporter[4993]: Traceback (most recent call last): Jan 10 08:41:46 hn-dlp ipa-ods-exporter[4993]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 08:41:46 hn-dlp ipa-ods-exporter[4993]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 08:41:46 hn-dlp ipa-ods-exporter[4993]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 08:41:46 hn-dlp ipa-ods-exporter[4993]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 08:41:46 hn-dlp ipa-ods-exporter[4993]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 08:41:46 hn-dlp ipa-ods-exporter[4993]: h = self.p11.import_public_key(**params) Jan 10 08:41:46 hn-dlp ipa-ods-exporter[4993]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 08:41:46 hn-dlp ipa-ods-exporter[4993]: raise DuplicationError("Public key with same ID already exists") Jan 10 08:41:46 hn-dlp ipa-ods-exporter[4993]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 08:41:47 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:41:47 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Failed with result 'exit-code'. Jan 10 08:41:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:41:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:42:20 hn-dlp systemd[1]: Stopping Berkeley Internet Name Domain (DNS) with native PKCS#11... Jan 10 08:42:20 hn-dlp named-pkcs11[4353]: received control channel command 'stop' Jan 10 08:42:20 hn-dlp named-pkcs11[4353]: shutting down: flushing changes Jan 10 08:42:20 hn-dlp named-pkcs11[4353]: stopping command channel on 127.0.0.1#953 Jan 10 08:42:20 hn-dlp named-pkcs11[4353]: stopping command channel on ::1#953 Jan 10 08:42:20 hn-dlp named-pkcs11[4353]: unloading DynDB instance 'ipa' Jan 10 08:42:20 hn-dlp named-pkcs11[4353]: zone 177.19.172.in-addr.arpa/IN: shutting down Jan 10 08:42:20 hn-dlp named-pkcs11[4353]: zone 187.19.172.in-addr.arpa/IN: shutting down Jan 10 08:42:20 hn-dlp named-pkcs11[4353]: zone 195.19.172.in-addr.arpa/IN: shutting down Jan 10 08:42:20 hn-dlp named-pkcs11[4353]: zone 197.19.172.in-addr.arpa/IN: shutting down Jan 10 08:42:20 hn-dlp named-pkcs11[4353]: zone ipa.example.local/IN: shutting down Jan 10 08:42:20 hn-dlp named-pkcs11[4353]: no longer listening on ::#53 Jan 10 08:42:20 hn-dlp named-pkcs11[4353]: no longer listening on 127.0.0.1#53 Jan 10 08:42:20 hn-dlp named-pkcs11[4353]: no longer listening on 172.19.187.2#53 Jan 10 08:42:21 hn-dlp named-pkcs11[4353]: exiting Jan 10 08:42:21 hn-dlp systemd[1]: named-pkcs11.service: Succeeded. Jan 10 08:42:21 hn-dlp systemd[1]: Stopped Berkeley Internet Name Domain (DNS) with native PKCS#11. Jan 10 08:42:21 hn-dlp systemd[1]: Starting SSSD Kerberos Cache Manager... Jan 10 08:42:21 hn-dlp systemd[1]: Started SSSD Kerberos Cache Manager. Jan 10 08:42:21 hn-dlp kcm[5034]: Starting up Jan 10 08:42:22 hn-dlp systemd[1]: Reloading. Jan 10 08:42:24 hn-dlp systemd[1]: Reloading. Jan 10 08:42:24 hn-dlp systemd[1]: Reloading Network Manager. Jan 10 08:42:24 hn-dlp NetworkManager[762]: <info> [1610264544.6056] audit: op="reload" arg="0" pid=5083 uid=0 result="success" Jan 10 08:42:24 hn-dlp NetworkManager[762]: <info> [1610264544.6484] config: signal: SIGHUP (no changes from disk) Jan 10 08:42:24 hn-dlp dbus-daemon[710]: [system] Activating via systemd: service name='org.freedesktop.resolve1' unit='dbus-org.freedesktop.resolve1.service' requested by ':1.10' (uid=0 pid=762 comm="/usr/sbin/NetworkManager --no-daemon " label="system_u:system_r:NetworkManager_t:s0") Jan 10 08:42:24 hn-dlp dbus-daemon[710]: [system] Activation via systemd failed for unit 'dbus-org.freedesktop.resolve1.service': Unit dbus-org.freedesktop.resolve1.service not found. Jan 10 08:42:24 hn-dlp systemd[1]: Reloaded Network Manager. Jan 10 08:42:24 hn-dlp systemd[1]: Stopping The Apache HTTP Server... Jan 10 08:42:33 hn-dlp systemd[1]: httpd.service: Succeeded. Jan 10 08:42:33 hn-dlp systemd[1]: Stopped The Apache HTTP Server. Jan 10 08:42:33 hn-dlp systemd[1]: Starting One-time temporary TLS key generation for httpd.service... Jan 10 08:42:33 hn-dlp systemd[1]: httpd-init.service: Succeeded. Jan 10 08:42:33 hn-dlp systemd[1]: Started One-time temporary TLS key generation for httpd.service. Jan 10 08:42:33 hn-dlp systemd[1]: Starting The Apache HTTP Server... Jan 10 08:42:33 hn-dlp ipa-httpd-kdcproxy[5101]: ipa: INFO: KDC proxy enabled Jan 10 08:42:33 hn-dlp ipa-httpd-kdcproxy[5101]: ipa-httpd-kdcproxy: INFO KDC proxy enabled Jan 10 08:42:34 hn-dlp systemd[1]: Started The Apache HTTP Server. Jan 10 08:42:34 hn-dlp httpd[5104]: Server configured, listening on: port 443, port 80 Jan 10 08:42:34 hn-dlp systemd[1]: Stopped IPA key daemon. Jan 10 08:42:35 hn-dlp platform-python[5012]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:42:35 hn-dlp platform-python[5012]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:42:35 hn-dlp platform-python[5012]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:42:36 hn-dlp systemd[1]: Reloading. Jan 10 08:42:37 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:42:37 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:42:43 hn-dlp platform-python[5406]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:42:43 hn-dlp platform-python[5407]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:42:43 hn-dlp platform-python[5406]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:42:43 hn-dlp platform-python[5406]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:42:43 hn-dlp platform-python[5407]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:42:43 hn-dlp platform-python[5407]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:42:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[5406]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:42:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[5407]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 08:42:43 hn-dlp ipa-ods-exporter[5406]: Traceback (most recent call last): Jan 10 08:42:43 hn-dlp ipa-ods-exporter[5406]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 08:42:43 hn-dlp ipa-ods-exporter[5406]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 08:42:43 hn-dlp ipa-ods-exporter[5406]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 08:42:43 hn-dlp ipa-ods-exporter[5406]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 08:42:43 hn-dlp ipa-ods-exporter[5406]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 08:42:43 hn-dlp ipa-ods-exporter[5406]: h = self.p11.import_public_key(**params) Jan 10 08:42:43 hn-dlp ipa-ods-exporter[5406]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 08:42:43 hn-dlp ipa-ods-exporter[5406]: raise DuplicationError("Public key with same ID already exists") Jan 10 08:42:43 hn-dlp ipa-ods-exporter[5406]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 08:42:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:42:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:42:45 hn-dlp systemd[1]: Reloading. Jan 10 08:42:46 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:42:46 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:42:47 hn-dlp systemd[1]: Reloading. Jan 10 08:42:49 hn-dlp systemd[1]: Started IPA key daemon. Jan 10 08:42:49 hn-dlp systemd[1]: Starting Generate rndc key for BIND (DNS)... Jan 10 08:42:49 hn-dlp systemd[1]: named-setup-rndc.service: Succeeded. Jan 10 08:42:49 hn-dlp systemd[1]: Started Generate rndc key for BIND (DNS). Jan 10 08:42:49 hn-dlp systemd[1]: Starting Berkeley Internet Name Domain (DNS) with native PKCS#11... Jan 10 08:42:50 hn-dlp bash[5567]: zone localhost.localdomain/IN: loaded serial 0 Jan 10 08:42:50 hn-dlp bash[5567]: zone localhost/IN: loaded serial 0 Jan 10 08:42:50 hn-dlp bash[5567]: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 0 Jan 10 08:42:50 hn-dlp bash[5567]: zone 1.0.0.127.in-addr.arpa/IN: loaded serial 0 Jan 10 08:42:50 hn-dlp bash[5567]: zone 0.in-addr.arpa/IN: loaded serial 0 Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: starting BIND 9.11.20-RedHat-9.11.20-5.el8 (Extended Support Version) <id:f3d1d66> Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: running on Linux x86_64 4.18.0-240.1.1.el8_3.x86_64 #1 SMP Thu Nov 19 17:20:08 UTC 2020 Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: built with '--build=x86_64-redhat-linux-gnu' '--host=x86_64-redhat-linux-gnu' '--program-prefix=' '--disable-dependency-tracking' '--prefix=/usr' '--exec-prefix=/usr' '--bindir=/usr/bin' '--sbindir=/usr/sbin' '--sysconfdir=/etc' '--datadir=/usr/share' '--includedir=/usr/include' '--libdir=/usr/lib64' '--libexecdir=/usr/libexec' '--sharedstatedir=/var/lib' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--with-python=/usr/libexec/platform-python' '--with-libtool' '--localstatedir=/var' '--enable-threads' '--enable-ipv6' '--enable-filter-aaaa' '--with-pic' '--disable-static' '--includedir=/usr/include/bind9' '--with-tuning=large' '--with-libidn2' '--enable-openssl-hash' '--with-geoip2' '--enable-native-pkcs11' '--with-pkcs11=/usr/lib64/pkcs11/libsofthsm2.so' '--with-dlopen=yes' '--with-dlz-ldap=yes' '--with-dlz-postgres=yes' '--with-dlz-mysql=yes' '--with-dlz-filesystem=yes' '--with-dlz-bdb=yes' '--with-gssapi=yes' '--disable-isc-spnego' '--with-lmdb=no' '--with-cmocka' '--enable-fixed-rrset' '--with-docbook-xsl=/usr/share/sgml/docbook/xsl-stylesheets' '--enable-full-report' 'build_alias=x86_64-redhat-linux-gnu' 'host_alias=x86_64-redhat-linux-gnu' 'CFLAGS= -O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection' 'LDFLAGS=-Wl,-z,relro -Wl,-z,now -specs=/usr/lib/rpm/redhat/redhat-hardened-ld' 'CPPFLAGS= -DDIG_SIGCHASE' 'PKG_CONFIG_PATH=:/usr/lib64/pkgconfig:/usr/share/pkgconfig' Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: running as: named-pkcs11 -u named -c /etc/named.conf Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: compiled by GCC 8.3.1 20191121 (Red Hat 8.3.1-5) Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: compiled with libxml2 version: 2.9.7 Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: linked to libxml2 version: 20907 Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: compiled with zlib version: 1.2.11 Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: linked to zlib version: 1.2.11 Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: threads support is enabled Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: ---------------------------------------------------- Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: BIND 9 is maintained by Internet Systems Consortium, Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: Inc. (ISC), a non-profit 501(c)(3) public-benefit Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: corporation. Support and training for BIND 9 are Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: available at https://www.isc.org/support Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: ---------------------------------------------------- Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: adjusted limit on open files from 262144 to 1048576 Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: found 4 CPUs, using 4 worker threads Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: using 3 UDP listeners per interface Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: using up to 21000 sockets Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: loading configuration from '/etc/named.conf' Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: unable to open '/etc/bind.keys'; using built-in keys instead Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: looking for GeoIP2 databases in '/usr/share/GeoIP' Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-Country.mmdb' Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-City.mmdb' Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: using default UDP/IPv4 port range: [32768, 60999] Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: using default UDP/IPv6 port range: [32768, 60999] Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: listening on IPv6 interfaces, port 53 Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: listening on IPv4 interface lo, 127.0.0.1#53 Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: listening on IPv4 interface ens18, 172.19.187.2#53 Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: generating session key for dynamic DNS Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: sizing zone task pool based on 6 zones Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: none:104: 'max-cache-size 90%' - setting to 1180MB (out of 1312MB) Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: set up managed keys zone for view _default, file '/var/named/dynamic/managed-keys.bind' Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: loading DynDB instance 'ipa' driver '/usr/lib64/bind/ldap.so' Jan 10 08:42:50 hn-dlp named-pkcs11[5572]: bind-dyndb-ldap version 11.3 compiled at 16:06:42 Sep 1 2020, compiler 8.3.1 20191121 (Red Hat 8.3.1-5) Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 10.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 16.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 17.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 18.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 19.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 20.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 21.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 22.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 23.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 24.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 25.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 26.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 27.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 28.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 29.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 30.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 31.172.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 168.192.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 64.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 65.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 66.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 67.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 68.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 69.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 70.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 71.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 72.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 73.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 74.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 75.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 76.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 77.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 78.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 79.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 80.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 81.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 82.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 83.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 84.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 85.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 86.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 87.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 88.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 89.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 90.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 91.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 92.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 93.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 94.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 95.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 96.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 97.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 98.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 99.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 100.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 101.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 102.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 103.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 104.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 105.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 106.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 107.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 108.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 109.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 110.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 111.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 112.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 113.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 114.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 115.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 116.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 117.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 118.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 119.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 120.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 121.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 122.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 123.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 124.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 125.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 126.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 127.100.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 127.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 254.169.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 2.0.192.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 100.51.198.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 113.0.203.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 255.255.255.255.IN-ADDR.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: D.F.IP6.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 8.E.F.IP6.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 9.E.F.IP6.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: A.E.F.IP6.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: B.E.F.IP6.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: 8.B.D.0.1.0.0.2.IP6.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: EMPTY.AS112.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: automatic empty zone: HOME.ARPA Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: none:104: 'max-cache-size 90%' - setting to 1180MB (out of 1312MB) Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: configuring command channel from '/etc/rndc.key' Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: command channel listening on 127.0.0.1#953 Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: configuring command channel from '/etc/rndc.key' Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: command channel listening on ::1#953 Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: managed-keys-zone: journal file is out of date: removing journal file Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: managed-keys-zone: loaded serial 229 Jan 10 08:42:51 hn-dlp systemd[1]: Started Berkeley Internet Name Domain (DNS) with native PKCS#11. Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: shutting down automatic empty zones to enable forwarding for domain '.' Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 0 Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: zone localhost/IN: loaded serial 0 Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: zone 0.in-addr.arpa/IN: loaded serial 0 Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: zone 1.0.0.127.in-addr.arpa/IN: loaded serial 0 Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: zone localhost.localdomain/IN: loaded serial 0 Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: all zones loaded Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: running Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: LDAP configuration for instance 'ipa' synchronized Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: LDAP data for instance 'ipa' are being synchronized, please ignore message 'all zones loaded' Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: managed-keys-zone: Key 20326 for zone . acceptance timer complete: key now trusted Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: forward zone 'int.example.local': loaded Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: forward zone 'srv.example.local': loaded Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: zone 177.19.172.in-addr.arpa/IN: loaded serial 1610264571 Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: zone 177.19.172.in-addr.arpa/IN: sending notifies (serial 1610264571) Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: zone 187.19.172.in-addr.arpa/IN: loaded serial 1610264571 Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: zone 187.19.172.in-addr.arpa/IN: sending notifies (serial 1610264571) Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: zone 195.19.172.in-addr.arpa/IN: sending notifies (serial 1610264571) Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: zone 195.19.172.in-addr.arpa/IN: loaded serial 1610264571 Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: zone 197.19.172.in-addr.arpa/IN: loaded serial 1610264571 Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: zone ipa.example.local/IN: loaded serial 1610264571 Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: 5 master zones from LDAP instance 'ipa' loaded (5 zones defined, 0 inactive, 0 failed to load) Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: zone 197.19.172.in-addr.arpa/IN: sending notifies (serial 1610264571) Jan 10 08:42:51 hn-dlp named-pkcs11[5572]: zone ipa.example.local/IN: sending notifies (serial 1610264571) Jan 10 08:42:56 hn-dlp named-pkcs11[5572]: zone 177.19.172.in-addr.arpa/IN: sending notifies (serial 1610264571) Jan 10 08:42:56 hn-dlp named-pkcs11[5572]: zone 187.19.172.in-addr.arpa/IN: sending notifies (serial 1610264571) Jan 10 08:42:56 hn-dlp named-pkcs11[5572]: zone 195.19.172.in-addr.arpa/IN: sending notifies (serial 1610264571) Jan 10 08:42:56 hn-dlp named-pkcs11[5572]: zone 197.19.172.in-addr.arpa/IN: sending notifies (serial 1610264571) Jan 10 08:42:56 hn-dlp named-pkcs11[5572]: zone ipa.example.local/IN: sending notifies (serial 1610264571) Jan 10 08:43:01 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[5464]: Kerberos authentication failed: Major (851968): Unspecified GSS failure. Minor code may provide more information, Minor (2529639107): No credentials cache found Jan 10 08:43:02 hn-dlp ipa-dnskeysyncd[5557]: ipa-dnskeysyncd: INFO LDAP bind... Jan 10 08:43:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:43:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:43:03 hn-dlp ipa-dnskeysyncd[5557]: ipa-dnskeysyncd: INFO Commencing sync process Jan 10 08:43:03 hn-dlp ipa-dnskeysyncd[5557]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-eeae1a850283edc8a00566c3dee263f0,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:43:03 hn-dlp ipa-dnskeysyncd[5557]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c04eba886f71eaf6942e4187a168530d,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:43:03 hn-dlp ipa-dnskeysyncd[5557]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-795ec7e363b4e831c99bc7751b006b8e,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:43:03 hn-dlp ipa-dnskeysyncd[5557]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-b16ee269a69c62ab190b78039c574e4b,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:43:03 hn-dlp ipa-dnskeysyncd[5557]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c5b715f14457ccb40f60e224b2220d7f,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:43:03 hn-dlp ipa-dnskeysyncd[5557]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-6e817263927b3519a7b5757e90ba5cfc,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:43:03 hn-dlp ipa-dnskeysyncd[5557]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100539Z-49de8f2954963b5779491cdacc9232c5,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:43:03 hn-dlp ipa-dnskeysyncd[5557]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-3e7a2e5aaa81fd5f1608f7824dd42b8e,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:43:03 hn-dlp ipa-dnskeysyncd[5557]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100552Z-2ff98d67ad4fd9c22202c132ec0d4141,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:43:03 hn-dlp ipa-dnskeysyncd[5557]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100556Z-708bc11ade0ce1fe2b4b061e80cc0035,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:43:03 hn-dlp ipa-dnskeysyncd[5557]: ipaserver.dnssec.keysyncer: INFO Initial LDAP dump is done, sychronizing with ODS and BIND Jan 10 08:43:05 hn-dlp systemd[1]: Starting Generate rndc key for BIND (DNS)... Jan 10 08:43:05 hn-dlp systemd[1]: named-setup-rndc.service: Succeeded. Jan 10 08:43:05 hn-dlp systemd[1]: Started Generate rndc key for BIND (DNS). Jan 10 08:43:05 hn-dlp systemd[1]: Starting One-time temporary TLS key generation for httpd.service... Jan 10 08:43:06 hn-dlp systemd[1]: httpd-init.service: Succeeded. Jan 10 08:43:06 hn-dlp systemd[1]: Started One-time temporary TLS key generation for httpd.service. Jan 10 08:43:12 hn-dlp named-pkcs11[5572]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 08:43:12 hn-dlp named-pkcs11[5572]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:43:12 hn-dlp platform-python[5594]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:43:13 hn-dlp platform-python[5594]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:43:13 hn-dlp platform-python[5594]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:43:13 hn-dlp ipa-dnskeysyncd[5557]: Traceback (most recent call last): Jan 10 08:43:13 hn-dlp ipa-dnskeysyncd[5557]: File "/usr/libexec/ipa/ipa-dnskeysyncd", line 116, in <module> Jan 10 08:43:13 hn-dlp ipa-dnskeysyncd[5557]: while ldap_connection.syncrepl_poll(all=1, msgid=ldap_search): Jan 10 08:43:13 hn-dlp ipa-dnskeysyncd[5557]: File "/usr/lib64/python3.6/site-packages/ldap/syncrepl.py", line 457, in syncrepl_poll Jan 10 08:43:13 hn-dlp ipa-dnskeysyncd[5557]: self.syncrepl_refreshdone() Jan 10 08:43:13 hn-dlp ipa-dnskeysyncd[5557]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/keysyncer.py", line 126, in syncrepl_refreshdone Jan 10 08:43:13 hn-dlp ipa-dnskeysyncd[5557]: self.hsm_replica_sync() Jan 10 08:43:13 hn-dlp ipa-dnskeysyncd[5557]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/keysyncer.py", line 192, in hsm_replica_sync Jan 10 08:43:13 hn-dlp ipa-dnskeysyncd[5557]: ipautil.run([paths.IPA_DNSKEYSYNCD_REPLICA]) Jan 10 08:43:13 hn-dlp ipa-dnskeysyncd[5557]: File "/usr/lib/python3.6/site-packages/ipapython/ipautil.py", line 598, in run Jan 10 08:43:13 hn-dlp ipa-dnskeysyncd[5557]: p.returncode, arg_string, output_log, error_log Jan 10 08:43:13 hn-dlp ipa-dnskeysyncd[5557]: ipapython.ipautil.CalledProcessError: CalledProcessError(Command ['/usr/libexec/ipa/ipa-dnskeysync-replica'] returned non-zero exit status 1: 'ipalib.plugable: DEBUG importing all plugin modules in ipaserver.plugins...\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.aci\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.automember\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.automount\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.baseldap\nipalib.plugable: DEBUG ipaserver.plugins.baseldap is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.baseuser\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.batch\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.ca\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.caacl\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.cert\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.certmap\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.certprofile\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.config\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.delegation\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.dns\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.dnsserver\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.dogtag\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.domainlevel\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.group\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbac\nipalib.plugable: DEBUG ipaserver.plugins.hbac is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbacrule\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbacsvc\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbactest\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.host\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hostgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.idrange\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.idviews\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.internal\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.join\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.krbtpolicy\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.ldap2\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.location\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.migration\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.misc\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.netgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.otp\nipalib.plugable: DEBUG ipaserver.plugins.otp is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.otpconfig\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.otptoken\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.passwd\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.permission\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.ping\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.pkinit\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.privilege\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.pwpolicy\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.rabase\nipalib.plugable: DEBUG ipaserver.plugins.rabase is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.radiusproxy\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.realmdomains\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.role\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.schema\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.selfservice\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.selinuxusermap\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.server\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.serverrole\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.serverroles\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.service\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.servicedelegation\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.session\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.stageuser\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudo\nipalib.plugable: DEBUG ipaserver.plugins.sudo is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudocmd\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudocmdgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudorule\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.topology\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.trust\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.user\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.vault\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.virtual\nipalib.plugable: DEBUG ipaserver.plugins.virtual is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.whoami\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.xmlserver\nipa-dnskeysync-replica: DEBUG Kerberos principal: ipa-dnskeysyncd/hn-dlp.ipa.example.local\nipalib.install.kinit: DEBUG Initializing principal ipa-dnskeysyncd/hn-dlp.ipa.example.local using keytab /etc/ipa/dnssec/ipa-dnskeysyncd.keytab\nipalib.install.kinit: DEBUG using ccache /tmp/ipa-dnskeysync-replica.ccache\nipalib.install.kinit: DEBUG Attempt 1/5: success\nipa-dnskeysync-replica: DEBUG Got TGT\nipa-dnskeysync-replica: DEBUG Connecting to LDAP\nipa-dnskeysync-replica: DEBUG Connected\nipapython.ipaldap: DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket conn=<ldap.ldapobject.SimpleLDAPObject object at 0x7fe53736ae10>\nipa-dnskeysync-replica: DEBUG master keys in local HSM: {\'0x218ea9686a3c2ae9bcad788d1c412dfd\', \'0x295cecf0ebb2c197928086c33c4b01ec\', \'0x7038dd6e887591694c48d05f0a73c87a\', \'0x302250bcd4461cbd5e5da827fa59de45\', \'0x57d2d80e09efdb200ff7a406f7acf6aa\'}\nipa-dnskeysync-replica: DEBUG master keys in LDAP HSM: {\'0x3e0cafd58625e3490b7650028f979d02\', \'0x295cecf0ebb2c197928086c33c4b01ec\', \'0x57d2d80e09efdb200ff7a406f7acf6aa\'}\nipa-dnskeysync-replica: DEBUG new master keys in LDAP HSM: {\'0x3e0cafd58625e3490b7650028f979d02\'}\nTraceback (most recent call last):\n File "/usr/libexec/ipa/ipa-dnskeysync-replica", line 189, in <module>\n ldap2replica_master_keys_sync(ldapkeydb, localhsm)\n File "/usr/libexec/ipa/ipa-dnskeysync-replica", line 80, in ldap2replica_master_keys_sync\n str_hexlify(mkey_id)\nValueError: Master key 0x3e0cafd58625e3490b7650028f979d02 in LDAP is missing key material referenced by ipaSecretKeyRefObject attribute\n') Jan 10 08:43:14 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:43:14 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Failed with result 'exit-code'. Jan 10 08:43:16 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:43:16.484179088 +0100] - INFO - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=caTonf-dlp.ipa.example.local" (nf-dlp:389): Replication bind with GSSAPI auth resumed Jan 10 08:43:40 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:44:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:44:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 45. Jan 10 08:44:03 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:44:03 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:44:05 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[5647]: Kerberos authentication failed: Major (851968): Unspecified GSS failure. Minor code may provide more information, Minor (2529639107): No credentials cache found Jan 10 08:44:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:44:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:44:14 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:44:14 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Scheduled restart job, restart counter is at 1. Jan 10 08:44:14 hn-dlp systemd[1]: Stopped IPA key daemon. Jan 10 08:44:14 hn-dlp systemd[1]: Started IPA key daemon. Jan 10 08:44:16 hn-dlp ipa-dnskeysyncd[5654]: ipa-dnskeysyncd: INFO LDAP bind... Jan 10 08:44:16 hn-dlp ipa-dnskeysyncd[5654]: ipa-dnskeysyncd: INFO Commencing sync process Jan 10 08:44:16 hn-dlp ipa-dnskeysyncd[5654]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-eeae1a850283edc8a00566c3dee263f0,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:44:16 hn-dlp ipa-dnskeysyncd[5654]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c04eba886f71eaf6942e4187a168530d,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:44:16 hn-dlp ipa-dnskeysyncd[5654]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-795ec7e363b4e831c99bc7751b006b8e,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:44:16 hn-dlp ipa-dnskeysyncd[5654]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-b16ee269a69c62ab190b78039c574e4b,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:44:16 hn-dlp ipa-dnskeysyncd[5654]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c5b715f14457ccb40f60e224b2220d7f,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:44:16 hn-dlp ipa-dnskeysyncd[5654]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-6e817263927b3519a7b5757e90ba5cfc,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:44:16 hn-dlp ipa-dnskeysyncd[5654]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100539Z-49de8f2954963b5779491cdacc9232c5,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:44:16 hn-dlp ipa-dnskeysyncd[5654]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-3e7a2e5aaa81fd5f1608f7824dd42b8e,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:44:16 hn-dlp ipa-dnskeysyncd[5654]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100552Z-2ff98d67ad4fd9c22202c132ec0d4141,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:44:16 hn-dlp ipa-dnskeysyncd[5654]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100556Z-708bc11ade0ce1fe2b4b061e80cc0035,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:44:16 hn-dlp ipa-dnskeysyncd[5654]: ipaserver.dnssec.keysyncer: INFO Initial LDAP dump is done, sychronizing with ODS and BIND Jan 10 08:44:19 hn-dlp platform-python[5659]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:44:19 hn-dlp platform-python[5659]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:44:19 hn-dlp platform-python[5659]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:44:20 hn-dlp ipa-dnskeysyncd[5654]: Traceback (most recent call last): Jan 10 08:44:20 hn-dlp ipa-dnskeysyncd[5654]: File "/usr/libexec/ipa/ipa-dnskeysyncd", line 116, in <module> Jan 10 08:44:20 hn-dlp ipa-dnskeysyncd[5654]: while ldap_connection.syncrepl_poll(all=1, msgid=ldap_search): Jan 10 08:44:20 hn-dlp ipa-dnskeysyncd[5654]: File "/usr/lib64/python3.6/site-packages/ldap/syncrepl.py", line 457, in syncrepl_poll Jan 10 08:44:20 hn-dlp ipa-dnskeysyncd[5654]: self.syncrepl_refreshdone() Jan 10 08:44:20 hn-dlp ipa-dnskeysyncd[5654]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/keysyncer.py", line 126, in syncrepl_refreshdone Jan 10 08:44:20 hn-dlp ipa-dnskeysyncd[5654]: self.hsm_replica_sync() Jan 10 08:44:20 hn-dlp ipa-dnskeysyncd[5654]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/keysyncer.py", line 192, in hsm_replica_sync Jan 10 08:44:20 hn-dlp ipa-dnskeysyncd[5654]: ipautil.run([paths.IPA_DNSKEYSYNCD_REPLICA]) Jan 10 08:44:20 hn-dlp ipa-dnskeysyncd[5654]: File "/usr/lib/python3.6/site-packages/ipapython/ipautil.py", line 598, in run Jan 10 08:44:20 hn-dlp ipa-dnskeysyncd[5654]: p.returncode, arg_string, output_log, error_log Jan 10 08:44:20 hn-dlp ipa-dnskeysyncd[5654]: ipapython.ipautil.CalledProcessError: CalledProcessError(Command ['/usr/libexec/ipa/ipa-dnskeysync-replica'] returned non-zero exit status 1: 'ipalib.plugable: DEBUG importing all plugin modules in ipaserver.plugins...\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.aci\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.automember\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.automount\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.baseldap\nipalib.plugable: DEBUG ipaserver.plugins.baseldap is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.baseuser\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.batch\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.ca\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.caacl\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.cert\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.certmap\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.certprofile\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.config\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.delegation\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.dns\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.dnsserver\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.dogtag\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.domainlevel\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.group\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbac\nipalib.plugable: DEBUG ipaserver.plugins.hbac is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbacrule\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbacsvc\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbactest\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.host\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hostgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.idrange\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.idviews\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.internal\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.join\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.krbtpolicy\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.ldap2\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.location\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.migration\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.misc\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.netgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.otp\nipalib.plugable: DEBUG ipaserver.plugins.otp is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.otpconfig\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.otptoken\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.passwd\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.permission\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.ping\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.pkinit\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.privilege\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.pwpolicy\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.rabase\nipalib.plugable: DEBUG ipaserver.plugins.rabase is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.radiusproxy\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.realmdomains\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.role\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.schema\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.selfservice\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.selinuxusermap\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.server\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.serverrole\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.serverroles\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.service\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.servicedelegation\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.session\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.stageuser\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudo\nipalib.plugable: DEBUG ipaserver.plugins.sudo is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudocmd\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudocmdgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudorule\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.topology\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.trust\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.user\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.vault\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.virtual\nipalib.plugable: DEBUG ipaserver.plugins.virtual is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.whoami\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.xmlserver\nipa-dnskeysync-replica: DEBUG Kerberos principal: ipa-dnskeysyncd/hn-dlp.ipa.example.local\nipalib.install.kinit: DEBUG Initializing principal ipa-dnskeysyncd/hn-dlp.ipa.example.local using keytab /etc/ipa/dnssec/ipa-dnskeysyncd.keytab\nipalib.install.kinit: DEBUG using ccache /tmp/ipa-dnskeysync-replica.ccache\nipalib.install.kinit: DEBUG Attempt 1/5: success\nipa-dnskeysync-replica: DEBUG Got TGT\nipa-dnskeysync-replica: DEBUG Connecting to LDAP\nipa-dnskeysync-replica: DEBUG Connected\nipapython.ipaldap: DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket conn=<ldap.ldapobject.SimpleLDAPObject object at 0x7f424933aa58>\nipa-dnskeysync-replica: DEBUG master keys in local HSM: {\'0x218ea9686a3c2ae9bcad788d1c412dfd\', \'0x7038dd6e887591694c48d05f0a73c87a\', \'0x295cecf0ebb2c197928086c33c4b01ec\', \'0x302250bcd4461cbd5e5da827fa59de45\', \'0x57d2d80e09efdb200ff7a406f7acf6aa\'}\nipa-dnskeysync-replica: DEBUG master keys in LDAP HSM: {\'0x57d2d80e09efdb200ff7a406f7acf6aa\', \'0x3e0cafd58625e3490b7650028f979d02\', \'0x295cecf0ebb2c197928086c33c4b01ec\'}\nipa-dnskeysync-replica: DEBUG new master keys in LDAP HSM: {\'0x3e0cafd58625e3490b7650028f979d02\'}\nTraceback (most recent call last):\n File "/usr/libexec/ipa/ipa-dnskeysync-replica", line 189, in <module>\n ldap2replica_master_keys_sync(ldapkeydb, localhsm)\n File "/usr/libexec/ipa/ipa-dnskeysync-replica", line 80, in ldap2replica_master_keys_sync\n str_hexlify(mkey_id)\nValueError: Master key 0x3e0cafd58625e3490b7650028f979d02 in LDAP is missing key material referenced by ipaSecretKeyRefObject attribute\n') Jan 10 08:44:20 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:44:20 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Failed with result 'exit-code'. Jan 10 08:44:54 hn-dlp systemd[1]: Stopping 389 Directory Server IPA-TECIN-NET.... Jan 10 08:44:54 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:44:54.811033508 +0100] - INFO - op_thread_cleanup - slapd shutting down - signaling operation threads - op stack size 6 max work q size 5 max work q stack size 5 Jan 10 08:44:54 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:44:54.903542915 +0100] - INFO - slapd_daemon - slapd shutting down - closing down internal subsystems and plugins Jan 10 08:45:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:45:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 46. Jan 10 08:45:06 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:45:06 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:45:08 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[5677]: Kerberos authentication failed: Major (851968): Unspecified GSS failure. Minor code may provide more information, Minor (2529639107): No credentials cache found Jan 10 08:45:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:45:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:45:12 hn-dlp named-pkcs11[5572]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:45:12 hn-dlp named-pkcs11[5572]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:45:16 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:45:16.747241795 +0100] - WARN - NSMMReplicationPlugin - acquire_replica - agmt="cn=meTonf-dlp.ipa.example.local" (nf-dlp:389): Unable to receive the response for a startReplication extended operation to consumer (Timed out). Will retry later. Jan 10 08:45:20 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:45:20 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Scheduled restart job, restart counter is at 2. Jan 10 08:45:20 hn-dlp systemd[1]: Stopped IPA key daemon. Jan 10 08:45:20 hn-dlp systemd[1]: Started IPA key daemon. Jan 10 08:45:41 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:45:53 hn-dlp winbindd[5688]: [2021/01/10 08:45:53.042696, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:45:53 hn-dlp winbindd[5688]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:45:53 hn-dlp winbindd[5688]: [2021/01/10 08:45:53.042872, 0] ../../source3/lib/smbldap.c:1059(smbldap_connect_system) Jan 10 08:45:53 hn-dlp winbindd[5688]: failed to bind to server ldapi://%2fvar%2frun%2fslapd-IPA-TECIN-NET.socket with dn="[Anonymous bind]" Error: Local error Jan 10 08:45:53 hn-dlp winbindd[5688]: #011(unknown) Jan 10 08:45:54 hn-dlp winbindd[5688]: [2021/01/10 08:45:54.044512, 0] ipa_sam.c:4865(pdb_init_ipasam) Jan 10 08:45:54 hn-dlp winbindd[5688]: Failed to get base DN. Jan 10 08:45:54 hn-dlp winbindd[5688]: [2021/01/10 08:45:54.044573, 0] ../../source3/passdb/pdb_interface.c:180(make_pdb_method_name) Jan 10 08:45:54 hn-dlp winbindd[5688]: pdb backend ipasam:ldapi://%2fvar%2frun%2fslapd-IPA-TECIN-NET.socket did not correctly init (error was NT_STATUS_UNSUCCESSFUL) Jan 10 08:45:58 hn-dlp ipa-dnskeysyncd[5684]: ipa-dnskeysyncd: CRITICAL Kerberos authentication failed: Major (851968): Unspecified GSS failure. Minor code may provide more information, Minor (2529638972): Generic error (see e-text) Jan 10 08:45:58 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:45:58 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Failed with result 'exit-code'. Jan 10 08:46:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:46:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 47. Jan 10 08:46:09 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:46:09 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:46:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[5693]: Kerberos authentication failed: Major (851968): Unspecified GSS failure. Minor code may provide more information, Minor (2529639107): No credentials cache found Jan 10 08:46:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:46:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:46:58 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:46:58 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Scheduled restart job, restart counter is at 3. Jan 10 08:46:58 hn-dlp systemd[1]: Stopped IPA key daemon. Jan 10 08:46:58 hn-dlp systemd[1]: Started IPA key daemon. Jan 10 08:47:00 hn-dlp ipa-dnskeysyncd[5701]: ipa-dnskeysyncd: CRITICAL Kerberos authentication failed: Major (851968): Unspecified GSS failure. Minor code may provide more information, Minor (2529638972): Generic error (see e-text) Jan 10 08:47:00 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:47:00 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Failed with result 'exit-code'. Jan 10 08:47:05 hn-dlp winbindd[5709]: [2021/01/10 08:47:05.494913, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:05 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:05 hn-dlp winbindd[5709]: [2021/01/10 08:47:05.495015, 0] ../../source3/lib/smbldap.c:1059(smbldap_connect_system) Jan 10 08:47:05 hn-dlp winbindd[5709]: failed to bind to server ldapi://%2fvar%2frun%2fslapd-IPA-TECIN-NET.socket with dn="[Anonymous bind]" Error: Local error Jan 10 08:47:05 hn-dlp winbindd[5709]: #011(unknown) Jan 10 08:47:06 hn-dlp winbindd[5709]: [2021/01/10 08:47:06.497700, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:06 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:07 hn-dlp winbindd[5709]: [2021/01/10 08:47:07.500502, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:07 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:08 hn-dlp winbindd[5709]: [2021/01/10 08:47:08.503132, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:08 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:09 hn-dlp winbindd[5709]: [2021/01/10 08:47:09.505827, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:09 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:10 hn-dlp winbindd[5709]: [2021/01/10 08:47:10.508475, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:10 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:11 hn-dlp winbindd[5709]: [2021/01/10 08:47:11.510991, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:11 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:12 hn-dlp named-pkcs11[5572]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:47:12 hn-dlp named-pkcs11[5572]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:47:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:47:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 48. Jan 10 08:47:12 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:47:12 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:47:12 hn-dlp winbindd[5709]: [2021/01/10 08:47:12.513544, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:12 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:13 hn-dlp winbindd[5709]: [2021/01/10 08:47:13.516677, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:13 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:14 hn-dlp winbindd[5709]: [2021/01/10 08:47:14.519227, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:14 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:14 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[5710]: Kerberos authentication failed: Major (851968): Unspecified GSS failure. Minor code may provide more information, Minor (2529639107): No credentials cache found Jan 10 08:47:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:47:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:47:15 hn-dlp winbindd[5709]: [2021/01/10 08:47:15.521844, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:15 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:16 hn-dlp winbindd[5709]: [2021/01/10 08:47:16.524430, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:16 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:17 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:47:17.267538983 +0100] - INFO - bdb_pre_close - Waiting for 4 database threads to stop Jan 10 08:47:17 hn-dlp winbindd[5709]: [2021/01/10 08:47:17.527485, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:17 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:18 hn-dlp winbindd[5709]: [2021/01/10 08:47:18.530028, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:18 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:19 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:47:19.224627046 +0100] - INFO - bdb_pre_close - All database threads now stopped Jan 10 08:47:19 hn-dlp winbindd[5709]: [2021/01/10 08:47:19.532586, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:19 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:20 hn-dlp named-pkcs11[5572]: LDAP error: Can't contact LDAP server: ldap_sync_poll() failed Jan 10 08:47:20 hn-dlp named-pkcs11[5572]: ldap_syncrepl will reconnect in 60 seconds Jan 10 08:47:20 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:47:20.109764025 +0100] - INFO - ldbm_back_instance_set_destructor - Set of instances destroyed Jan 10 08:47:20 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:47:20.118150368 +0100] - INFO - connection_post_shutdown_cleanup - slapd shutting down - freed 5 work q stack objects - freed 6 op stack objects Jan 10 08:47:20 hn-dlp ns-slapd[4282]: [10/Jan/2021:08:47:20.119049925 +0100] - INFO - main - slapd stopped. Jan 10 08:47:20 hn-dlp winbindd[5709]: [2021/01/10 08:47:20.535238, 0] ipa_sam.c:4554(bind_callback_cleanup) Jan 10 08:47:20 hn-dlp winbindd[5709]: kerberos error: code=-1765328324, message=Generic error (see e-text) Jan 10 08:47:20 hn-dlp systemd[1]: dirsrv@IPA-TECIN-NET.service: Succeeded. Jan 10 08:47:20 hn-dlp systemd[1]: Stopped 389 Directory Server IPA-TECIN-NET.. Jan 10 08:47:20 hn-dlp systemd[1]: Starting 389 Directory Server IPA-TECIN-NET.... Jan 10 08:47:21 hn-dlp winbindd[5709]: [2021/01/10 08:47:21.535794, 0] ipa_sam.c:4865(pdb_init_ipasam) Jan 10 08:47:21 hn-dlp winbindd[5709]: Failed to get base DN. Jan 10 08:47:21 hn-dlp winbindd[5709]: [2021/01/10 08:47:21.535865, 0] ../../source3/passdb/pdb_interface.c:180(make_pdb_method_name) Jan 10 08:47:21 hn-dlp winbindd[5709]: pdb backend ipasam:ldapi://%2fvar%2frun%2fslapd-IPA-TECIN-NET.socket did not correctly init (error was NT_STATUS_UNSUCCESSFUL) Jan 10 08:47:21 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:21.645303640 +0100] - INFO - slapd_extract_cert - CA CERT NAME: IPA.example.local IPA CA Jan 10 08:47:21 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:21.646586201 +0100] - INFO - slapd_extract_cert - CA CERT NAME: DC=tecin,DC=net,E=info@example.local,CN=TecIn-CA Jan 10 08:47:21 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:21.648327632 +0100] - WARN - Security Initialization - SSL alert: Sending pin request to SVRCore. You may need to run systemd-tty-ask-password-agent to provide the password. Jan 10 08:47:21 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:21.894993632 +0100] - INFO - slapd_extract_cert - SERVER CERT NAME: Server-Cert Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.414367216 +0100] - INFO - Security Initialization - SSL info: Enabling default cipher set. Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.415335599 +0100] - INFO - Security Initialization - SSL info: Configured NSS Ciphers Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.418159797 +0100] - INFO - Security Initialization - SSL info: #011TLS_AES_128_GCM_SHA256: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.424152307 +0100] - INFO - Security Initialization - SSL info: #011TLS_CHACHA20_POLY1305_SHA256: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.427880460 +0100] - INFO - Security Initialization - SSL info: #011TLS_AES_256_GCM_SHA384: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.431826205 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.432480900 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.433035615 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.433500174 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.434141952 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.434791154 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.435345548 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.436002886 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.436612825 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.437240125 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.437860095 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.438328123 +0100] - INFO - Security Initialization - SSL info: #011TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.438811753 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.439252420 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.439708816 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.440299045 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_128_CBC_SHA: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.440831796 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.441348092 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_256_CBC_SHA: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.441771521 +0100] - INFO - Security Initialization - SSL info: #011TLS_DHE_RSA_WITH_AES_256_CBC_SHA256: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.442321287 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_128_GCM_SHA256: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.442932737 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_256_GCM_SHA384: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.443602780 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_128_CBC_SHA: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.444106800 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_128_CBC_SHA256: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.444641777 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_256_CBC_SHA: enabled Jan 10 08:47:22 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:22.445183621 +0100] - INFO - Security Initialization - SSL info: #011TLS_RSA_WITH_AES_256_CBC_SHA256: enabled Jan 10 08:47:23 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:23.042894472 +0100] - INFO - Security Initialization - slapd_ssl_init2 - Configured SSL version range: min: TLS1.2, max: TLS1.3 Jan 10 08:47:23 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:23.044216085 +0100] - INFO - Security Initialization - slapd_ssl_init2 - NSS adjusted SSL version range: min: TLS1.2, max: TLS1.3 Jan 10 08:47:23 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:23.045166137 +0100] - INFO - main - 389-Directory/1.4.3.8 B2020.357.1921 starting up Jan 10 08:47:23 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:23.045790439 +0100] - INFO - main - Setting the maximum file descriptor limit to: 262144 Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.043531221 +0100] - INFO - PBKDF2_SHA256 - Based on CPU performance, chose 2048 rounds Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.047023325 +0100] - INFO - ldbm_instance_config_cachememsize_set - force a minimal value 512000 Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.053216320 +0100] - INFO - ldbm_instance_config_cachememsize_set - force a minimal value 512000 Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.058976880 +0100] - INFO - ldbm_instance_config_cachememsize_set - force a minimal value 512000 Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.064931169 +0100] - NOTICE - ldbm_back_start - found 1343712k physical memory Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.065646187 +0100] - NOTICE - ldbm_back_start - found 250528k available Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.072330315 +0100] - NOTICE - ldbm_back_start - cache autosizing: db cache: 33592k Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.080373568 +0100] - NOTICE - ldbm_back_start - cache autosizing: userRoot entry cache (3 total): 65536k Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.088617593 +0100] - NOTICE - ldbm_back_start - cache autosizing: userRoot dn cache (3 total): 65536k Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.096567559 +0100] - NOTICE - ldbm_back_start - cache autosizing: ipaca entry cache (3 total): 65536k Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.104754635 +0100] - NOTICE - ldbm_back_start - cache autosizing: ipaca dn cache (3 total): 65536k Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.113129493 +0100] - NOTICE - ldbm_back_start - cache autosizing: changelog entry cache (3 total): 65536k Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.120732959 +0100] - NOTICE - ldbm_back_start - cache autosizing: changelog dn cache (3 total): 65536k Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.128817555 +0100] - NOTICE - ldbm_back_start - total cache size: 430172405 B; Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.136452801 +0100] - WARN - ldbm_back_start - It is highly likely your memory configuration of all backends will EXCEED your systems memory. Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.144406526 +0100] - WARN - ldbm_back_start - In a future release this WILL prevent server start up. You MUST alter your configuration. Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.152382465 +0100] - WARN - ldbm_back_start - Total entry cache size: 128270336 B; dbcache size: 27519221 B; available memory size: 256540672 B; Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.160386449 +0100] - WARN - ldbm_back_start - This can be corrected by altering the values of nsslapd-cache-autosize, nsslapd-cache-autosize-split and nsslapd-dncachememsize Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.465017085 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher AES Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.466019319 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.728446982 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher 3DES Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.729531655 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.730200466 +0100] - ERR - attrcrypt_init - All prepared ciphers are not available. Please disable attribute encryption. Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.997655142 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher AES Jan 10 08:47:24 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:24.998713751 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.267001058 +0100] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for cipher 3DES Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.267790040 +0100] - ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed since the key is wrapped. To recover the encrypted contents, keep the wrapped symmetric key value. Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.268400721 +0100] - ERR - attrcrypt_init - All prepared ciphers are not available. Please disable attribute encryption. Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.888330088 +0100] - ERR - schema-compat-plugin - scheduled schema-compat-plugin tree scan in about 5 seconds after the server startup! Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.918970817 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=groups,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.919978538 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=computers,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.920684793 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=ng,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.921568139 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target ou=sudoers,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.922205283 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=users,cn=compat,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.922801739 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.923552038 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.924326855 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.927046463 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.928022113 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.931157723 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.932071516 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.933077901 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.933897421 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.935289531 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.937555463 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=vaults,cn=kra,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.953531391 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:25 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:25.954597729 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=tecin,dc=net does not exist Jan 10 08:47:26 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:26.050995299 +0100] - WARN - NSACLPlugin - acl_parse - The ACL target cn=automember rebuild membership,cn=tasks,cn=config does not exist Jan 10 08:47:26 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:26.056202036 +0100] - ERR - cos-plugin - cos_dn_defs_cb - Skipping CoS Definition cn=Password Policy,cn=accounts,dc=ipa,dc=tecin,dc=net--no CoS Templates found, which should be added before the CoS Definition. Jan 10 08:47:26 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:26.109194721 +0100] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/hn-dlp.ipa.example.local@IPA.example.local] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328324 (Generic error (see e-text)) Jan 10 08:47:26 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:26.121752495 +0100] - INFO - slapd_daemon - slapd started. Listening on All Interfaces port 389 for LDAP requests Jan 10 08:47:26 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:26.122500688 +0100] - INFO - slapd_daemon - Listening on All Interfaces port 636 for LDAPS requests Jan 10 08:47:26 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:26.122991712 +0100] - INFO - slapd_daemon - Listening on /var/run/slapd-IPA-TECIN-NET.socket for LDAPI requests Jan 10 08:47:26 hn-dlp systemd[1]: Started 389 Directory Server IPA-TECIN-NET.. Jan 10 08:47:26 hn-dlp systemd[1]: Stopping Kerberos 5 KDC... Jan 10 08:47:26 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:26.183066692 +0100] - ERR - schema-compat-plugin - schema-compat-plugin tree scan will start in about 5 seconds! Jan 10 08:47:26 hn-dlp systemd[1]: krb5kdc.service: Succeeded. Jan 10 08:47:26 hn-dlp systemd[1]: Stopped Kerberos 5 KDC. Jan 10 08:47:26 hn-dlp systemd[1]: Starting Kerberos 5 KDC... Jan 10 08:47:26 hn-dlp systemd[1]: krb5kdc.service: Can't open PID file /var/run/krb5kdc.pid (yet?) after start: No such file or directory Jan 10 08:47:26 hn-dlp systemd[1]: Started Kerberos 5 KDC. Jan 10 08:47:26 hn-dlp systemd[1]: Stopping Kerberos 5 Password-changing and Administration... Jan 10 08:47:27 hn-dlp systemd[1]: kadmin.service: Succeeded. Jan 10 08:47:27 hn-dlp systemd[1]: Stopped Kerberos 5 Password-changing and Administration. Jan 10 08:47:27 hn-dlp systemd[1]: Starting Kerberos 5 Password-changing and Administration... Jan 10 08:47:27 hn-dlp systemd[1]: Started Kerberos 5 Password-changing and Administration. Jan 10 08:47:27 hn-dlp systemd[1]: Stopping Berkeley Internet Name Domain (DNS) with native PKCS#11... Jan 10 08:47:27 hn-dlp named-pkcs11[5572]: received control channel command 'stop' Jan 10 08:47:27 hn-dlp named-pkcs11[5572]: shutting down: flushing changes Jan 10 08:47:27 hn-dlp named-pkcs11[5572]: stopping command channel on 127.0.0.1#953 Jan 10 08:47:27 hn-dlp named-pkcs11[5572]: stopping command channel on ::1#953 Jan 10 08:47:27 hn-dlp named-pkcs11[5572]: unloading DynDB instance 'ipa' Jan 10 08:47:27 hn-dlp named-pkcs11[5572]: zone 177.19.172.in-addr.arpa/IN: shutting down Jan 10 08:47:27 hn-dlp named-pkcs11[5572]: zone 187.19.172.in-addr.arpa/IN: shutting down Jan 10 08:47:27 hn-dlp named-pkcs11[5572]: zone 195.19.172.in-addr.arpa/IN: shutting down Jan 10 08:47:27 hn-dlp named-pkcs11[5572]: zone 197.19.172.in-addr.arpa/IN: shutting down Jan 10 08:47:27 hn-dlp named-pkcs11[5572]: zone ipa.example.local/IN: shutting down Jan 10 08:47:27 hn-dlp named-pkcs11[5572]: no longer listening on ::#53 Jan 10 08:47:27 hn-dlp named-pkcs11[5572]: no longer listening on 127.0.0.1#53 Jan 10 08:47:27 hn-dlp named-pkcs11[5572]: no longer listening on 172.19.187.2#53 Jan 10 08:47:28 hn-dlp named-pkcs11[5572]: exiting Jan 10 08:47:28 hn-dlp systemd[1]: named-pkcs11.service: Succeeded. Jan 10 08:47:28 hn-dlp systemd[1]: Stopped Berkeley Internet Name Domain (DNS) with native PKCS#11. Jan 10 08:47:28 hn-dlp systemd[1]: Starting Generate rndc key for BIND (DNS)... Jan 10 08:47:28 hn-dlp systemd[1]: named-setup-rndc.service: Succeeded. Jan 10 08:47:28 hn-dlp systemd[1]: Started Generate rndc key for BIND (DNS). Jan 10 08:47:28 hn-dlp systemd[1]: Starting Berkeley Internet Name Domain (DNS) with native PKCS#11... Jan 10 08:47:28 hn-dlp bash[5806]: zone localhost.localdomain/IN: loaded serial 0 Jan 10 08:47:28 hn-dlp bash[5806]: zone localhost/IN: loaded serial 0 Jan 10 08:47:28 hn-dlp bash[5806]: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 0 Jan 10 08:47:28 hn-dlp bash[5806]: zone 1.0.0.127.in-addr.arpa/IN: loaded serial 0 Jan 10 08:47:28 hn-dlp bash[5806]: zone 0.in-addr.arpa/IN: loaded serial 0 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: starting BIND 9.11.20-RedHat-9.11.20-5.el8 (Extended Support Version) <id:f3d1d66> Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: running on Linux x86_64 4.18.0-240.1.1.el8_3.x86_64 #1 SMP Thu Nov 19 17:20:08 UTC 2020 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: built with '--build=x86_64-redhat-linux-gnu' '--host=x86_64-redhat-linux-gnu' '--program-prefix=' '--disable-dependency-tracking' '--prefix=/usr' '--exec-prefix=/usr' '--bindir=/usr/bin' '--sbindir=/usr/sbin' '--sysconfdir=/etc' '--datadir=/usr/share' '--includedir=/usr/include' '--libdir=/usr/lib64' '--libexecdir=/usr/libexec' '--sharedstatedir=/var/lib' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--with-python=/usr/libexec/platform-python' '--with-libtool' '--localstatedir=/var' '--enable-threads' '--enable-ipv6' '--enable-filter-aaaa' '--with-pic' '--disable-static' '--includedir=/usr/include/bind9' '--with-tuning=large' '--with-libidn2' '--enable-openssl-hash' '--with-geoip2' '--enable-native-pkcs11' '--with-pkcs11=/usr/lib64/pkcs11/libsofthsm2.so' '--with-dlopen=yes' '--with-dlz-ldap=yes' '--with-dlz-postgres=yes' '--with-dlz-mysql=yes' '--with-dlz-filesystem=yes' '--with-dlz-bdb=yes' '--with-gssapi=yes' '--disable-isc-spnego' '--with-lmdb=no' '--with-cmocka' '--enable-fixed-rrset' '--with-docbook-xsl=/usr/share/sgml/docbook/xsl-stylesheets' '--enable-full-report' 'build_alias=x86_64-redhat-linux-gnu' 'host_alias=x86_64-redhat-linux-gnu' 'CFLAGS= -O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection' 'LDFLAGS=-Wl,-z,relro -Wl,-z,now -specs=/usr/lib/rpm/redhat/redhat-hardened-ld' 'CPPFLAGS= -DDIG_SIGCHASE' 'PKG_CONFIG_PATH=:/usr/lib64/pkgconfig:/usr/share/pkgconfig' Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: running as: named-pkcs11 -u named -c /etc/named.conf Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: compiled by GCC 8.3.1 20191121 (Red Hat 8.3.1-5) Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: compiled with libxml2 version: 2.9.7 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: linked to libxml2 version: 20907 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: compiled with zlib version: 1.2.11 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: linked to zlib version: 1.2.11 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: threads support is enabled Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: ---------------------------------------------------- Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: BIND 9 is maintained by Internet Systems Consortium, Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: Inc. (ISC), a non-profit 501(c)(3) public-benefit Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: corporation. Support and training for BIND 9 are Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: available at https://www.isc.org/support Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: ---------------------------------------------------- Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: adjusted limit on open files from 262144 to 1048576 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: found 4 CPUs, using 4 worker threads Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: using 3 UDP listeners per interface Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: using up to 21000 sockets Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: loading configuration from '/etc/named.conf' Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: unable to open '/etc/bind.keys'; using built-in keys instead Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: looking for GeoIP2 databases in '/usr/share/GeoIP' Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-Country.mmdb' Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-City.mmdb' Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: using default UDP/IPv4 port range: [32768, 60999] Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: using default UDP/IPv6 port range: [32768, 60999] Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: listening on IPv6 interfaces, port 53 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: listening on IPv4 interface lo, 127.0.0.1#53 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: listening on IPv4 interface ens18, 172.19.187.2#53 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: generating session key for dynamic DNS Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: sizing zone task pool based on 6 zones Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: none:104: 'max-cache-size 90%' - setting to 1180MB (out of 1312MB) Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: set up managed keys zone for view _default, file '/var/named/dynamic/managed-keys.bind' Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: loading DynDB instance 'ipa' driver '/usr/lib64/bind/ldap.so' Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: bind-dyndb-ldap version 11.3 compiled at 16:06:42 Sep 1 2020, compiler 8.3.1 20191121 (Red Hat 8.3.1-5) Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 10.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 16.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 17.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 18.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 19.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 20.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 21.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 22.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 23.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 24.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 25.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 26.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 27.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 28.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 29.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 30.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 31.172.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 168.192.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 64.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 65.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 66.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 67.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 68.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 69.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 70.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 71.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 72.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 73.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 74.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 75.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 76.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 77.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 78.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 79.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 80.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 81.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 82.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 83.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 84.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 85.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 86.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 87.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 88.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 89.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 90.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 91.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 92.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 93.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 94.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 95.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 96.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 97.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 98.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 99.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 100.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 101.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 102.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 103.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 104.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 105.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 106.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 107.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 108.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 109.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 110.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 111.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 112.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 113.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 114.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 115.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp systemd[1]: Started Berkeley Internet Name Domain (DNS) with native PKCS#11. Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 116.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 117.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 118.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 119.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 120.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 121.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 122.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 123.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 124.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 125.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 126.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 127.100.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 127.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 254.169.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 2.0.192.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 100.51.198.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 113.0.203.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 255.255.255.255.IN-ADDR.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: D.F.IP6.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 8.E.F.IP6.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 9.E.F.IP6.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: A.E.F.IP6.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: B.E.F.IP6.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: 8.B.D.0.1.0.0.2.IP6.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: EMPTY.AS112.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: automatic empty zone: HOME.ARPA Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: none:104: 'max-cache-size 90%' - setting to 1180MB (out of 1312MB) Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: configuring command channel from '/etc/rndc.key' Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: command channel listening on 127.0.0.1#953 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: configuring command channel from '/etc/rndc.key' Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: command channel listening on ::1#953 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: managed-keys-zone: journal file is out of date: removing journal file Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: managed-keys-zone: loaded serial 230 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: zone 10.IN-ADDR.ARPA/IN: shutting down Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: shutting down automatic empty zones to enable forwarding for domain '.' Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: zone 111.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: zone 0.in-addr.arpa/IN: loaded serial 0 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: zone EMPTY.AS112.ARPA/IN: shutting down Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 0 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: zone localhost/IN: loaded serial 0 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: zone localhost.localdomain/IN: loaded serial 0 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: zone 1.0.0.127.in-addr.arpa/IN: loaded serial 0 Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: all zones loaded Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: running Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: LDAP configuration for instance 'ipa' synchronized Jan 10 08:47:28 hn-dlp named-pkcs11[5811]: managed-keys-zone: Key 20326 for zone . acceptance timer complete: key now trusted Jan 10 08:47:28 hn-dlp systemd[1]: Stopping The Apache HTTP Server... Jan 10 08:47:29 hn-dlp named-pkcs11[5811]: LDAP data for instance 'ipa' are being synchronized, please ignore message 'all zones loaded' Jan 10 08:47:29 hn-dlp named-pkcs11[5811]: forward zone 'int.example.local': loaded Jan 10 08:47:29 hn-dlp named-pkcs11[5811]: forward zone 'srv.example.local': loaded Jan 10 08:47:29 hn-dlp named-pkcs11[5811]: zone 177.19.172.in-addr.arpa/IN: loaded serial 1610264849 Jan 10 08:47:29 hn-dlp named-pkcs11[5811]: zone 187.19.172.in-addr.arpa/IN: loaded serial 1610264849 Jan 10 08:47:29 hn-dlp named-pkcs11[5811]: zone 187.19.172.in-addr.arpa/IN: sending notifies (serial 1610264849) Jan 10 08:47:29 hn-dlp named-pkcs11[5811]: zone 177.19.172.in-addr.arpa/IN: sending notifies (serial 1610264849) Jan 10 08:47:29 hn-dlp named-pkcs11[5811]: zone 195.19.172.in-addr.arpa/IN: loaded serial 1610264849 Jan 10 08:47:29 hn-dlp named-pkcs11[5811]: zone 197.19.172.in-addr.arpa/IN: loaded serial 1610264849 Jan 10 08:47:29 hn-dlp named-pkcs11[5811]: zone ipa.example.local/IN: loaded serial 1610264849 Jan 10 08:47:29 hn-dlp named-pkcs11[5811]: 5 master zones from LDAP instance 'ipa' loaded (5 zones defined, 0 inactive, 0 failed to load) Jan 10 08:47:29 hn-dlp named-pkcs11[5811]: zone 195.19.172.in-addr.arpa/IN: sending notifies (serial 1610264849) Jan 10 08:47:29 hn-dlp named-pkcs11[5811]: zone ipa.example.local/IN: sending notifies (serial 1610264849) Jan 10 08:47:29 hn-dlp named-pkcs11[5811]: zone 197.19.172.in-addr.arpa/IN: sending notifies (serial 1610264849) Jan 10 08:47:30 hn-dlp systemd[1]: httpd.service: Succeeded. Jan 10 08:47:30 hn-dlp systemd[1]: Stopped The Apache HTTP Server. Jan 10 08:47:30 hn-dlp systemd[1]: Starting One-time temporary TLS key generation for httpd.service... Jan 10 08:47:30 hn-dlp systemd[1]: httpd-init.service: Succeeded. Jan 10 08:47:30 hn-dlp systemd[1]: Started One-time temporary TLS key generation for httpd.service. Jan 10 08:47:30 hn-dlp systemd[1]: Starting The Apache HTTP Server... Jan 10 08:47:31 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:31.192393379 +0100] - ERR - schema-compat-plugin - warning: no entries set up under ou=sudoers,dc=ipa,dc=tecin,dc=net Jan 10 08:47:31 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:31.194174558 +0100] - ERR - schema-compat-plugin - warning: no entries set up under cn=ng, cn=compat,dc=ipa,dc=tecin,dc=net Jan 10 08:47:31 hn-dlp ipa-httpd-kdcproxy[5835]: ipa: INFO: KDC proxy enabled Jan 10 08:47:31 hn-dlp ipa-httpd-kdcproxy[5835]: ipa-httpd-kdcproxy: INFO KDC proxy enabled Jan 10 08:47:31 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:31.697213090 +0100] - ERR - schema-compat-plugin - warning: no entries set up under cn=computers, cn=compat,dc=ipa,dc=tecin,dc=net Jan 10 08:47:31 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:47:31.698294489 +0100] - ERR - schema-compat-plugin - Finished plugin initialization. Jan 10 08:47:31 hn-dlp systemd[1]: Started The Apache HTTP Server. Jan 10 08:47:31 hn-dlp httpd[5839]: Server configured, listening on: port 443, port 80 Jan 10 08:47:31 hn-dlp systemd[1]: Stopping IPA Custodia Service... Jan 10 08:47:31 hn-dlp systemd[1]: ipa-custodia.service: Succeeded. Jan 10 08:47:31 hn-dlp systemd[1]: Stopped IPA Custodia Service. Jan 10 08:47:31 hn-dlp systemd[1]: Starting IPA Custodia Service... Jan 10 08:47:32 hn-dlp ipa-custodia[5916]: 2021-01-10 08:47:32 - custodia - Custodia instance <main> Jan 10 08:47:33 hn-dlp ipa-custodia[5916]: 2021-01-10 08:47:33 - server - Serving on Unix socket /run/httpd/ipa-custodia.sock Jan 10 08:47:33 hn-dlp systemd[1]: Started IPA Custodia Service. Jan 10 08:47:33 hn-dlp systemd[1]: Stopped target PKI Tomcat Server. Jan 10 08:47:33 hn-dlp systemd[1]: Stopping PKI Tomcat Server. Jan 10 08:47:33 hn-dlp systemd[1]: Stopping PKI Tomcat Server pki-tomcat... Jan 10 08:47:33 hn-dlp server[6120]: Java virtual machine used: /usr/lib/jvm/jre-openjdk/bin/java Jan 10 08:47:33 hn-dlp server[6120]: classpath used: /usr/share/tomcat/bin/bootstrap.jar:/usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/ant.jar:/usr/share/java/ant-launcher.jar:/usr/lib/jvm/java/lib/tools.jar Jan 10 08:47:33 hn-dlp server[6120]: main class used: org.apache.catalina.startup.Bootstrap Jan 10 08:47:33 hn-dlp server[6120]: flags used: -Dcom.redhat.fips=false Jan 10 08:47:33 hn-dlp server[6120]: options used: -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager Jan 10 08:47:33 hn-dlp server[6120]: arguments used: stop Jan 10 08:47:34 hn-dlp named-pkcs11[5811]: zone 177.19.172.in-addr.arpa/IN: sending notifies (serial 1610264849) Jan 10 08:47:34 hn-dlp named-pkcs11[5811]: zone 187.19.172.in-addr.arpa/IN: sending notifies (serial 1610264849) Jan 10 08:47:34 hn-dlp named-pkcs11[5811]: zone 195.19.172.in-addr.arpa/IN: sending notifies (serial 1610264849) Jan 10 08:47:38 hn-dlp systemd[1]: pki-tomcatd@pki-tomcat.service: Succeeded. Jan 10 08:47:38 hn-dlp systemd[1]: Stopped PKI Tomcat Server pki-tomcat. Jan 10 08:47:38 hn-dlp systemd[1]: Starting PKI Tomcat Server pki-tomcat... Jan 10 08:47:42 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:47:43 hn-dlp server[6275]: Java virtual machine used: /usr/lib/jvm/jre-openjdk/bin/java Jan 10 08:47:43 hn-dlp server[6275]: classpath used: /usr/share/tomcat/bin/bootstrap.jar:/usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/ant.jar:/usr/share/java/ant-launcher.jar:/usr/lib/jvm/java/lib/tools.jar Jan 10 08:47:43 hn-dlp server[6275]: main class used: org.apache.catalina.startup.Bootstrap Jan 10 08:47:43 hn-dlp server[6275]: flags used: -Dcom.redhat.fips=false Jan 10 08:47:43 hn-dlp server[6275]: options used: -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Djava.security.manager -Djava.security.policy==/var/lib/pki/pki-tomcat/conf/catalina.policy Jan 10 08:47:43 hn-dlp server[6275]: arguments used: start Jan 10 08:47:44 hn-dlp ipa-pki-wait-running[6276]: pki.client: /usr/libexec/ipa/ipa-pki-wait-running:63: The subsystem in PKIConnection.__init__() has been deprecated (https://www.dogtagpki.org/wiki/PKI_10.8_Python_Changes). Jan 10 08:47:44 hn-dlp ipa-pki-wait-running[6276]: ipa-pki-wait-running: Created connection http://hn-dlp.ipa.example.local:8080/ca Jan 10 08:47:44 hn-dlp ipa-pki-wait-running[6276]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Max retries exceeded with url: /ca/admin/ca/getStatus (Caused by NewConnectionError('<urllib3.connection.HTTPConnection object at 0x7f3eee81ab70>: Failed to establish a new connection: [Errno 111] Connection refused',)) Jan 10 08:47:45 hn-dlp ipa-pki-wait-running[6276]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Max retries exceeded with url: /ca/admin/ca/getStatus (Caused by NewConnectionError('<urllib3.connection.HTTPConnection object at 0x7f3eee81af60>: Failed to establish a new connection: [Errno 111] Connection refused',)) Jan 10 08:47:45 hn-dlp server[6275]: WARNING: Some of the specified [protocols] are not supported by the SSL engine and have been skipped: [[TLSv1, TLSv1.1]] Jan 10 08:47:47 hn-dlp ipa-pki-wait-running[6276]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 08:47:49 hn-dlp ipa-pki-wait-running[6276]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 08:47:51 hn-dlp ipa-pki-wait-running[6276]: ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='hn-dlp.ipa.example.local', port=8080): Read timed out. (read timeout=1.0) Jan 10 08:47:53 hn-dlp ipa-pki-wait-running[6276]: ipa-pki-wait-running: Success, subsystem ca is running! Jan 10 08:47:53 hn-dlp systemd[1]: Started PKI Tomcat Server pki-tomcat. Jan 10 08:47:53 hn-dlp systemd[1]: Reached target PKI Tomcat Server. Jan 10 08:47:53 hn-dlp systemd[1]: Stopping Samba SMB Daemon... Jan 10 08:47:53 hn-dlp systemd[1]: smb.service: Succeeded. Jan 10 08:47:53 hn-dlp systemd[1]: Stopped Samba SMB Daemon. Jan 10 08:47:53 hn-dlp systemd[1]: Starting Samba SMB Daemon... Jan 10 08:48:01 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:48:01 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Scheduled restart job, restart counter is at 4. Jan 10 08:48:01 hn-dlp systemd[1]: Stopped IPA key daemon. Jan 10 08:48:01 hn-dlp systemd[1]: Started IPA key daemon. Jan 10 08:48:01 hn-dlp smbd[6411]: [2021/01/10 08:48:01.786657, 0] ../../lib/util/become_daemon.c:136(daemon_ready) Jan 10 08:48:01 hn-dlp systemd[1]: Started Samba SMB Daemon. Jan 10 08:48:01 hn-dlp smbd[6411]: daemon_ready: daemon 'smbd' finished starting up and ready to serve connections Jan 10 08:48:01 hn-dlp systemd[1]: Stopping Samba Winbind Daemon... Jan 10 08:48:01 hn-dlp winbindd[4956]: [2021/01/10 08:48:01.828339, 0] ../../source3/winbindd/winbindd.c:245(winbindd_sig_term_handler) Jan 10 08:48:01 hn-dlp winbindd[4956]: Got sig[15] terminate (is_parent=0) Jan 10 08:48:01 hn-dlp winbindd[4939]: [2021/01/10 08:48:01.828574, 0] ../../source3/winbindd/winbindd.c:245(winbindd_sig_term_handler) Jan 10 08:48:01 hn-dlp winbindd[4939]: Got sig[15] terminate (is_parent=1) Jan 10 08:48:01 hn-dlp winbindd[4957]: [2021/01/10 08:48:01.829517, 0] ../../source3/winbindd/winbindd.c:245(winbindd_sig_term_handler) Jan 10 08:48:01 hn-dlp winbindd[4957]: Got sig[15] terminate (is_parent=0) Jan 10 08:48:01 hn-dlp winbindd[4955]: [2021/01/10 08:48:01.829785, 0] ../../source3/winbindd/winbindd.c:245(winbindd_sig_term_handler) Jan 10 08:48:01 hn-dlp winbindd[4955]: Got sig[15] terminate (is_parent=0) Jan 10 08:48:02 hn-dlp systemd[1]: winbind.service: Succeeded. Jan 10 08:48:02 hn-dlp systemd[1]: Stopped Samba Winbind Daemon. Jan 10 08:48:02 hn-dlp systemd[1]: Starting Samba Winbind Daemon... Jan 10 08:48:03 hn-dlp winbindd[6428]: [2021/01/10 08:48:03.022273, 0] ../../source3/winbindd/winbindd_cache.c:3205(initialize_winbindd_cache) Jan 10 08:48:03 hn-dlp winbindd[6428]: initialize_winbindd_cache: clearing cache and re-creating with version number 2 Jan 10 08:48:03 hn-dlp winbindd[6428]: [2021/01/10 08:48:03.069837, 0] ../../lib/util/become_daemon.c:136(daemon_ready) Jan 10 08:48:03 hn-dlp winbindd[6428]: daemon_ready: daemon 'winbindd' finished starting up and ready to serve connections Jan 10 08:48:03 hn-dlp systemd[1]: Started Samba Winbind Daemon. Jan 10 08:48:03 hn-dlp systemd[1]: ipa-otpd.socket: Succeeded. Jan 10 08:48:03 hn-dlp systemd[1]: Closed ipa-otpd socket. Jan 10 08:48:03 hn-dlp systemd[1]: Stopping ipa-otpd socket. Jan 10 08:48:03 hn-dlp systemd[1]: Listening on ipa-otpd socket. Jan 10 08:48:03 hn-dlp systemd[1]: Stopping IPA key daemon... Jan 10 08:48:03 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Succeeded. Jan 10 08:48:03 hn-dlp systemd[1]: Stopped IPA key daemon. Jan 10 08:48:03 hn-dlp systemd[1]: Started IPA key daemon. Jan 10 08:48:06 hn-dlp ipa-dnskeysyncd[6440]: ipa-dnskeysyncd: INFO LDAP bind... Jan 10 08:48:06 hn-dlp ipa-dnskeysyncd[6440]: ipa-dnskeysyncd: INFO Commencing sync process Jan 10 08:48:06 hn-dlp ipa-dnskeysyncd[6440]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-eeae1a850283edc8a00566c3dee263f0,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:48:06 hn-dlp ipa-dnskeysyncd[6440]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c04eba886f71eaf6942e4187a168530d,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:48:06 hn-dlp ipa-dnskeysyncd[6440]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-795ec7e363b4e831c99bc7751b006b8e,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:48:06 hn-dlp ipa-dnskeysyncd[6440]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-b16ee269a69c62ab190b78039c574e4b,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:48:06 hn-dlp ipa-dnskeysyncd[6440]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c5b715f14457ccb40f60e224b2220d7f,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:48:06 hn-dlp ipa-dnskeysyncd[6440]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-6e817263927b3519a7b5757e90ba5cfc,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:48:06 hn-dlp ipa-dnskeysyncd[6440]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100539Z-49de8f2954963b5779491cdacc9232c5,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:48:06 hn-dlp ipa-dnskeysyncd[6440]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-3e7a2e5aaa81fd5f1608f7824dd42b8e,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:48:06 hn-dlp ipa-dnskeysyncd[6440]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100552Z-2ff98d67ad4fd9c22202c132ec0d4141,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:48:06 hn-dlp ipa-dnskeysyncd[6440]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100556Z-708bc11ade0ce1fe2b4b061e80cc0035,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:48:06 hn-dlp ipa-dnskeysyncd[6440]: ipaserver.dnssec.keysyncer: INFO Initial LDAP dump is done, sychronizing with ODS and BIND Jan 10 08:48:10 hn-dlp platform-python[6446]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:48:11 hn-dlp platform-python[6446]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:48:11 hn-dlp platform-python[6446]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:48:12 hn-dlp ipa-dnskeysyncd[6440]: Traceback (most recent call last): Jan 10 08:48:12 hn-dlp ipa-dnskeysyncd[6440]: File "/usr/libexec/ipa/ipa-dnskeysyncd", line 116, in <module> Jan 10 08:48:12 hn-dlp ipa-dnskeysyncd[6440]: while ldap_connection.syncrepl_poll(all=1, msgid=ldap_search): Jan 10 08:48:12 hn-dlp ipa-dnskeysyncd[6440]: File "/usr/lib64/python3.6/site-packages/ldap/syncrepl.py", line 457, in syncrepl_poll Jan 10 08:48:12 hn-dlp ipa-dnskeysyncd[6440]: self.syncrepl_refreshdone() Jan 10 08:48:12 hn-dlp ipa-dnskeysyncd[6440]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/keysyncer.py", line 126, in syncrepl_refreshdone Jan 10 08:48:12 hn-dlp ipa-dnskeysyncd[6440]: self.hsm_replica_sync() Jan 10 08:48:12 hn-dlp ipa-dnskeysyncd[6440]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/keysyncer.py", line 192, in hsm_replica_sync Jan 10 08:48:12 hn-dlp ipa-dnskeysyncd[6440]: ipautil.run([paths.IPA_DNSKEYSYNCD_REPLICA]) Jan 10 08:48:12 hn-dlp ipa-dnskeysyncd[6440]: File "/usr/lib/python3.6/site-packages/ipapython/ipautil.py", line 598, in run Jan 10 08:48:12 hn-dlp ipa-dnskeysyncd[6440]: p.returncode, arg_string, output_log, error_log Jan 10 08:48:12 hn-dlp ipa-dnskeysyncd[6440]: ipapython.ipautil.CalledProcessError: CalledProcessError(Command ['/usr/libexec/ipa/ipa-dnskeysync-replica'] returned non-zero exit status 1: 'ipalib.plugable: DEBUG importing all plugin modules in ipaserver.plugins...\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.aci\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.automember\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.automount\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.baseldap\nipalib.plugable: DEBUG ipaserver.plugins.baseldap is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.baseuser\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.batch\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.ca\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.caacl\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.cert\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.certmap\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.certprofile\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.config\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.delegation\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.dns\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.dnsserver\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.dogtag\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.domainlevel\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.group\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbac\nipalib.plugable: DEBUG ipaserver.plugins.hbac is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbacrule\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbacsvc\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbactest\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.host\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hostgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.idrange\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.idviews\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.internal\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.join\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.krbtpolicy\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.ldap2\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.location\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.migration\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.misc\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.netgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.otp\nipalib.plugable: DEBUG ipaserver.plugins.otp is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.otpconfig\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.otptoken\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.passwd\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.permission\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.ping\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.pkinit\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.privilege\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.pwpolicy\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.rabase\nipalib.plugable: DEBUG ipaserver.plugins.rabase is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.radiusproxy\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.realmdomains\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.role\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.schema\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.selfservice\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.selinuxusermap\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.server\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.serverrole\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.serverroles\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.service\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.servicedelegation\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.session\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.stageuser\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudo\nipalib.plugable: DEBUG ipaserver.plugins.sudo is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudocmd\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudocmdgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudorule\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.topology\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.trust\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.user\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.vault\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.virtual\nipalib.plugable: DEBUG ipaserver.plugins.virtual is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.whoami\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.xmlserver\nipa-dnskeysync-replica: DEBUG Kerberos principal: ipa-dnskeysyncd/hn-dlp.ipa.example.local\nipalib.install.kinit: DEBUG Initializing principal ipa-dnskeysyncd/hn-dlp.ipa.example.local using keytab /etc/ipa/dnssec/ipa-dnskeysyncd.keytab\nipalib.install.kinit: DEBUG using ccache /tmp/ipa-dnskeysync-replica.ccache\nipalib.install.kinit: DEBUG Attempt 1/5: success\nipa-dnskeysync-replica: DEBUG Got TGT\nipa-dnskeysync-replica: DEBUG Connecting to LDAP\nipa-dnskeysync-replica: DEBUG Connected\nipapython.ipaldap: DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket conn=<ldap.ldapobject.SimpleLDAPObject object at 0x7f39f49d0e10>\nipa-dnskeysync-replica: DEBUG master keys in local HSM: {\'0x295cecf0ebb2c197928086c33c4b01ec\', \'0x57d2d80e09efdb200ff7a406f7acf6aa\', \'0x302250bcd4461cbd5e5da827fa59de45\', \'0x218ea9686a3c2ae9bcad788d1c412dfd\', \'0x7038dd6e887591694c48d05f0a73c87a\'}\nipa-dnskeysync-replica: DEBUG master keys in LDAP HSM: {\'0x3e0cafd58625e3490b7650028f979d02\', \'0x295cecf0ebb2c197928086c33c4b01ec\', \'0x57d2d80e09efdb200ff7a406f7acf6aa\'}\nipa-dnskeysync-replica: DEBUG new master keys in LDAP HSM: {\'0x3e0cafd58625e3490b7650028f979d02\'}\nTraceback (most recent call last):\n File "/usr/libexec/ipa/ipa-dnskeysync-replica", line 189, in <module>\n ldap2replica_master_keys_sync(ldapkeydb, localhsm)\n File "/usr/libexec/ipa/ipa-dnskeysync-replica", line 80, in ldap2replica_master_keys_sync\n str_hexlify(mkey_id)\nValueError: Master key 0x3e0cafd58625e3490b7650028f979d02 in LDAP is missing key material referenced by ipaSecretKeyRefObject attribute\n') Jan 10 08:48:12 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:48:12 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Failed with result 'exit-code'. Jan 10 08:48:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:48:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 49. Jan 10 08:48:15 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:48:15 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:48:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[6459]: Kerberos authentication failed: Major (851968): Unspecified GSS failure. Minor code may provide more information, Minor (2529639107): No credentials cache found Jan 10 08:48:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:48:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:49:12 hn-dlp named-pkcs11[5811]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 08:49:12 hn-dlp named-pkcs11[5811]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:49:12 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:49:12 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Scheduled restart job, restart counter is at 1. Jan 10 08:49:12 hn-dlp systemd[1]: Stopped IPA key daemon. Jan 10 08:49:12 hn-dlp systemd[1]: Started IPA key daemon. Jan 10 08:49:15 hn-dlp ipa-dnskeysyncd[6469]: ipa-dnskeysyncd: INFO LDAP bind... Jan 10 08:49:15 hn-dlp ipa-dnskeysyncd[6469]: ipa-dnskeysyncd: INFO Commencing sync process Jan 10 08:49:15 hn-dlp ipa-dnskeysyncd[6469]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-eeae1a850283edc8a00566c3dee263f0,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:49:15 hn-dlp ipa-dnskeysyncd[6469]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c04eba886f71eaf6942e4187a168530d,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:49:15 hn-dlp ipa-dnskeysyncd[6469]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-795ec7e363b4e831c99bc7751b006b8e,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:49:15 hn-dlp ipa-dnskeysyncd[6469]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-b16ee269a69c62ab190b78039c574e4b,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:49:15 hn-dlp ipa-dnskeysyncd[6469]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c5b715f14457ccb40f60e224b2220d7f,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:49:15 hn-dlp ipa-dnskeysyncd[6469]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-6e817263927b3519a7b5757e90ba5cfc,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:49:15 hn-dlp ipa-dnskeysyncd[6469]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100539Z-49de8f2954963b5779491cdacc9232c5,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:49:15 hn-dlp ipa-dnskeysyncd[6469]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-3e7a2e5aaa81fd5f1608f7824dd42b8e,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:49:15 hn-dlp ipa-dnskeysyncd[6469]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100552Z-2ff98d67ad4fd9c22202c132ec0d4141,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:49:15 hn-dlp ipa-dnskeysyncd[6469]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100556Z-708bc11ade0ce1fe2b4b061e80cc0035,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:49:15 hn-dlp ipa-dnskeysyncd[6469]: ipaserver.dnssec.keysyncer: INFO Initial LDAP dump is done, sychronizing with ODS and BIND Jan 10 08:49:17 hn-dlp platform-python[6474]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:49:17 hn-dlp platform-python[6474]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:49:17 hn-dlp platform-python[6474]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:49:18 hn-dlp ipa-dnskeysyncd[6469]: Traceback (most recent call last): Jan 10 08:49:18 hn-dlp ipa-dnskeysyncd[6469]: File "/usr/libexec/ipa/ipa-dnskeysyncd", line 116, in <module> Jan 10 08:49:18 hn-dlp ipa-dnskeysyncd[6469]: while ldap_connection.syncrepl_poll(all=1, msgid=ldap_search): Jan 10 08:49:18 hn-dlp ipa-dnskeysyncd[6469]: File "/usr/lib64/python3.6/site-packages/ldap/syncrepl.py", line 457, in syncrepl_poll Jan 10 08:49:18 hn-dlp ipa-dnskeysyncd[6469]: self.syncrepl_refreshdone() Jan 10 08:49:18 hn-dlp ipa-dnskeysyncd[6469]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/keysyncer.py", line 126, in syncrepl_refreshdone Jan 10 08:49:18 hn-dlp ipa-dnskeysyncd[6469]: self.hsm_replica_sync() Jan 10 08:49:18 hn-dlp ipa-dnskeysyncd[6469]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/keysyncer.py", line 192, in hsm_replica_sync Jan 10 08:49:18 hn-dlp ipa-dnskeysyncd[6469]: ipautil.run([paths.IPA_DNSKEYSYNCD_REPLICA]) Jan 10 08:49:18 hn-dlp ipa-dnskeysyncd[6469]: File "/usr/lib/python3.6/site-packages/ipapython/ipautil.py", line 598, in run Jan 10 08:49:18 hn-dlp ipa-dnskeysyncd[6469]: p.returncode, arg_string, output_log, error_log Jan 10 08:49:18 hn-dlp ipa-dnskeysyncd[6469]: ipapython.ipautil.CalledProcessError: CalledProcessError(Command ['/usr/libexec/ipa/ipa-dnskeysync-replica'] returned non-zero exit status 1: 'ipalib.plugable: DEBUG importing all plugin modules in ipaserver.plugins...\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.aci\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.automember\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.automount\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.baseldap\nipalib.plugable: DEBUG ipaserver.plugins.baseldap is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.baseuser\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.batch\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.ca\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.caacl\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.cert\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.certmap\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.certprofile\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.config\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.delegation\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.dns\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.dnsserver\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.dogtag\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.domainlevel\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.group\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbac\nipalib.plugable: DEBUG ipaserver.plugins.hbac is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbacrule\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbacsvc\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbactest\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.host\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hostgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.idrange\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.idviews\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.internal\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.join\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.krbtpolicy\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.ldap2\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.location\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.migration\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.misc\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.netgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.otp\nipalib.plugable: DEBUG ipaserver.plugins.otp is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.otpconfig\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.otptoken\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.passwd\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.permission\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.ping\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.pkinit\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.privilege\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.pwpolicy\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.rabase\nipalib.plugable: DEBUG ipaserver.plugins.rabase is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.radiusproxy\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.realmdomains\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.role\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.schema\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.selfservice\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.selinuxusermap\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.server\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.serverrole\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.serverroles\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.service\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.servicedelegation\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.session\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.stageuser\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudo\nipalib.plugable: DEBUG ipaserver.plugins.sudo is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudocmd\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudocmdgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudorule\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.topology\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.trust\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.user\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.vault\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.virtual\nipalib.plugable: DEBUG ipaserver.plugins.virtual is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.whoami\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.xmlserver\nipa-dnskeysync-replica: DEBUG Kerberos principal: ipa-dnskeysyncd/hn-dlp.ipa.example.local\nipalib.install.kinit: DEBUG Initializing principal ipa-dnskeysyncd/hn-dlp.ipa.example.local using keytab /etc/ipa/dnssec/ipa-dnskeysyncd.keytab\nipalib.install.kinit: DEBUG using ccache /tmp/ipa-dnskeysync-replica.ccache\nipalib.install.kinit: DEBUG Attempt 1/5: success\nipa-dnskeysync-replica: DEBUG Got TGT\nipa-dnskeysync-replica: DEBUG Connecting to LDAP\nipa-dnskeysync-replica: DEBUG Connected\nipapython.ipaldap: DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket conn=<ldap.ldapobject.SimpleLDAPObject object at 0x7f74ac2c7e10>\nipa-dnskeysync-replica: DEBUG master keys in local HSM: {\'0x302250bcd4461cbd5e5da827fa59de45\', \'0x7038dd6e887591694c48d05f0a73c87a\', \'0x218ea9686a3c2ae9bcad788d1c412dfd\', \'0x57d2d80e09efdb200ff7a406f7acf6aa\', \'0x295cecf0ebb2c197928086c33c4b01ec\'}\nipa-dnskeysync-replica: DEBUG master keys in LDAP HSM: {\'0x3e0cafd58625e3490b7650028f979d02\', \'0x57d2d80e09efdb200ff7a406f7acf6aa\', \'0x295cecf0ebb2c197928086c33c4b01ec\'}\nipa-dnskeysync-replica: DEBUG new master keys in LDAP HSM: {\'0x3e0cafd58625e3490b7650028f979d02\'}\nTraceback (most recent call last):\n File "/usr/libexec/ipa/ipa-dnskeysync-replica", line 189, in <module>\n ldap2replica_master_keys_sync(ldapkeydb, localhsm)\n File "/usr/libexec/ipa/ipa-dnskeysync-replica", line 80, in ldap2replica_master_keys_sync\n str_hexlify(mkey_id)\nValueError: Master key 0x3e0cafd58625e3490b7650028f979d02 in LDAP is missing key material referenced by ipaSecretKeyRefObject attribute\n') Jan 10 08:49:18 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:49:18 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Failed with result 'exit-code'. Jan 10 08:49:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:49:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 50. Jan 10 08:49:19 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:49:19 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:49:24 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[6481]: Kerberos authentication failed: Major (851968): Unspecified GSS failure. Minor code may provide more information, Minor (2529639107): No credentials cache found Jan 10 08:49:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:49:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:49:26 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:49:26.254128837 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=meToha-dlp.ipa.example.local" (ha-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 08:49:42 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:49:51 hn-dlp kcm[5034]: Shutting down (status = 0) Jan 10 08:49:52 hn-dlp systemd[1]: sssd-kcm.service: Succeeded. Jan 10 08:49:58 hn-dlp systemd[1]: Stopping Berkeley Internet Name Domain (DNS) with native PKCS#11... Jan 10 08:49:58 hn-dlp named-pkcs11[5811]: received control channel command 'stop' Jan 10 08:49:58 hn-dlp named-pkcs11[5811]: shutting down: flushing changes Jan 10 08:49:58 hn-dlp named-pkcs11[5811]: stopping command channel on 127.0.0.1#953 Jan 10 08:49:58 hn-dlp named-pkcs11[5811]: stopping command channel on ::1#953 Jan 10 08:49:58 hn-dlp named-pkcs11[5811]: unloading DynDB instance 'ipa' Jan 10 08:49:58 hn-dlp named-pkcs11[5811]: zone 177.19.172.in-addr.arpa/IN: shutting down Jan 10 08:49:58 hn-dlp named-pkcs11[5811]: zone 187.19.172.in-addr.arpa/IN: shutting down Jan 10 08:49:58 hn-dlp named-pkcs11[5811]: zone 195.19.172.in-addr.arpa/IN: shutting down Jan 10 08:49:58 hn-dlp named-pkcs11[5811]: zone 197.19.172.in-addr.arpa/IN: shutting down Jan 10 08:49:58 hn-dlp named-pkcs11[5811]: zone ipa.example.local/IN: shutting down Jan 10 08:49:58 hn-dlp named-pkcs11[5811]: no longer listening on ::#53 Jan 10 08:49:58 hn-dlp named-pkcs11[5811]: no longer listening on 127.0.0.1#53 Jan 10 08:49:58 hn-dlp named-pkcs11[5811]: no longer listening on 172.19.187.2#53 Jan 10 08:49:59 hn-dlp named-pkcs11[5811]: exiting Jan 10 08:49:59 hn-dlp systemd[1]: named-pkcs11.service: Succeeded. Jan 10 08:49:59 hn-dlp systemd[1]: Stopped Berkeley Internet Name Domain (DNS) with native PKCS#11. Jan 10 08:49:59 hn-dlp systemd[1]: Starting SSSD Kerberos Cache Manager... Jan 10 08:49:59 hn-dlp systemd[1]: Started SSSD Kerberos Cache Manager. Jan 10 08:49:59 hn-dlp kcm[6578]: Starting up Jan 10 08:50:00 hn-dlp systemd[1]: Reloading. Jan 10 08:50:02 hn-dlp systemd[1]: Reloading. Jan 10 08:50:02 hn-dlp systemd[1]: Reloading Network Manager. Jan 10 08:50:02 hn-dlp NetworkManager[762]: <info> [1610265002.5338] audit: op="reload" arg="0" pid=6632 uid=0 result="success" Jan 10 08:50:02 hn-dlp NetworkManager[762]: <info> [1610265002.5627] config: signal: SIGHUP (no changes from disk) Jan 10 08:50:02 hn-dlp systemd[1]: Reloaded Network Manager. Jan 10 08:50:02 hn-dlp systemd[1]: Stopping The Apache HTTP Server... Jan 10 08:50:18 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:50:18 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Scheduled restart job, restart counter is at 2. Jan 10 08:50:18 hn-dlp systemd[1]: Stopped IPA key daemon. Jan 10 08:50:18 hn-dlp systemd[1]: Started IPA key daemon. Jan 10 08:50:21 hn-dlp ipa-dnskeysyncd[6636]: ipa-dnskeysyncd: INFO LDAP bind... Jan 10 08:50:21 hn-dlp ipa-dnskeysyncd[6636]: ipa-dnskeysyncd: INFO Commencing sync process Jan 10 08:50:21 hn-dlp ipa-dnskeysyncd[6636]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-eeae1a850283edc8a00566c3dee263f0,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:50:21 hn-dlp ipa-dnskeysyncd[6636]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c04eba886f71eaf6942e4187a168530d,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:50:21 hn-dlp ipa-dnskeysyncd[6636]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-795ec7e363b4e831c99bc7751b006b8e,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:50:21 hn-dlp ipa-dnskeysyncd[6636]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-b16ee269a69c62ab190b78039c574e4b,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:50:21 hn-dlp ipa-dnskeysyncd[6636]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c5b715f14457ccb40f60e224b2220d7f,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:50:21 hn-dlp ipa-dnskeysyncd[6636]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-6e817263927b3519a7b5757e90ba5cfc,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:50:21 hn-dlp ipa-dnskeysyncd[6636]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100539Z-49de8f2954963b5779491cdacc9232c5,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:50:21 hn-dlp ipa-dnskeysyncd[6636]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-3e7a2e5aaa81fd5f1608f7824dd42b8e,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:50:21 hn-dlp ipa-dnskeysyncd[6636]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100552Z-2ff98d67ad4fd9c22202c132ec0d4141,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:50:21 hn-dlp ipa-dnskeysyncd[6636]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100556Z-708bc11ade0ce1fe2b4b061e80cc0035,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:50:21 hn-dlp ipa-dnskeysyncd[6636]: ipaserver.dnssec.keysyncer: INFO Initial LDAP dump is done, sychronizing with ODS and BIND Jan 10 08:50:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:50:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 51. Jan 10 08:50:24 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:50:24 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:50:25 hn-dlp platform-python[6641]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:50:26 hn-dlp platform-python[6641]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:50:26 hn-dlp platform-python[6641]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:50:26 hn-dlp ipa-dnskeysyncd[6636]: Traceback (most recent call last): Jan 10 08:50:26 hn-dlp ipa-dnskeysyncd[6636]: File "/usr/libexec/ipa/ipa-dnskeysyncd", line 116, in <module> Jan 10 08:50:26 hn-dlp ipa-dnskeysyncd[6636]: while ldap_connection.syncrepl_poll(all=1, msgid=ldap_search): Jan 10 08:50:26 hn-dlp ipa-dnskeysyncd[6636]: File "/usr/lib64/python3.6/site-packages/ldap/syncrepl.py", line 457, in syncrepl_poll Jan 10 08:50:26 hn-dlp ipa-dnskeysyncd[6636]: self.syncrepl_refreshdone() Jan 10 08:50:26 hn-dlp ipa-dnskeysyncd[6636]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/keysyncer.py", line 126, in syncrepl_refreshdone Jan 10 08:50:26 hn-dlp ipa-dnskeysyncd[6636]: self.hsm_replica_sync() Jan 10 08:50:26 hn-dlp ipa-dnskeysyncd[6636]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/keysyncer.py", line 192, in hsm_replica_sync Jan 10 08:50:26 hn-dlp ipa-dnskeysyncd[6636]: ipautil.run([paths.IPA_DNSKEYSYNCD_REPLICA]) Jan 10 08:50:26 hn-dlp ipa-dnskeysyncd[6636]: File "/usr/lib/python3.6/site-packages/ipapython/ipautil.py", line 598, in run Jan 10 08:50:26 hn-dlp ipa-dnskeysyncd[6636]: p.returncode, arg_string, output_log, error_log Jan 10 08:50:26 hn-dlp ipa-dnskeysyncd[6636]: ipapython.ipautil.CalledProcessError: CalledProcessError(Command ['/usr/libexec/ipa/ipa-dnskeysync-replica'] returned non-zero exit status 1: 'ipalib.plugable: DEBUG importing all plugin modules in ipaserver.plugins...\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.aci\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.automember\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.automount\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.baseldap\nipalib.plugable: DEBUG ipaserver.plugins.baseldap is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.baseuser\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.batch\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.ca\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.caacl\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.cert\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.certmap\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.certprofile\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.config\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.delegation\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.dns\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.dnsserver\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.dogtag\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.domainlevel\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.group\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbac\nipalib.plugable: DEBUG ipaserver.plugins.hbac is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbacrule\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbacsvc\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hbactest\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.host\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.hostgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.idrange\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.idviews\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.internal\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.join\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.krbtpolicy\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.ldap2\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.location\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.migration\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.misc\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.netgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.otp\nipalib.plugable: DEBUG ipaserver.plugins.otp is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.otpconfig\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.otptoken\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.passwd\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.permission\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.ping\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.pkinit\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.privilege\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.pwpolicy\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.rabase\nipalib.plugable: DEBUG ipaserver.plugins.rabase is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.radiusproxy\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.realmdomains\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.role\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.schema\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.selfservice\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.selinuxusermap\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.server\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.serverrole\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.serverroles\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.service\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.servicedelegation\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.session\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.stageuser\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudo\nipalib.plugable: DEBUG ipaserver.plugins.sudo is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudocmd\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudocmdgroup\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.sudorule\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.topology\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.trust\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.user\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.vault\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.virtual\nipalib.plugable: DEBUG ipaserver.plugins.virtual is not a valid plugin module\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.whoami\nipalib.plugable: DEBUG importing plugin module ipaserver.plugins.xmlserver\nipa-dnskeysync-replica: DEBUG Kerberos principal: ipa-dnskeysyncd/hn-dlp.ipa.example.local\nipalib.install.kinit: DEBUG Initializing principal ipa-dnskeysyncd/hn-dlp.ipa.example.local using keytab /etc/ipa/dnssec/ipa-dnskeysyncd.keytab\nipalib.install.kinit: DEBUG using ccache /tmp/ipa-dnskeysync-replica.ccache\nipalib.install.kinit: DEBUG Attempt 1/5: success\nipa-dnskeysync-replica: DEBUG Got TGT\nipa-dnskeysync-replica: DEBUG Connecting to LDAP\nipa-dnskeysync-replica: DEBUG Connected\nipapython.ipaldap: DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-IPA-TECIN-NET.socket conn=<ldap.ldapobject.SimpleLDAPObject object at 0x7f36bd5395c0>\nipa-dnskeysync-replica: DEBUG master keys in local HSM: {\'0x302250bcd4461cbd5e5da827fa59de45\', \'0x295cecf0ebb2c197928086c33c4b01ec\', \'0x218ea9686a3c2ae9bcad788d1c412dfd\', \'0x7038dd6e887591694c48d05f0a73c87a\', \'0x57d2d80e09efdb200ff7a406f7acf6aa\'}\nipa-dnskeysync-replica: DEBUG master keys in LDAP HSM: {\'0x3e0cafd58625e3490b7650028f979d02\', \'0x295cecf0ebb2c197928086c33c4b01ec\', \'0x57d2d80e09efdb200ff7a406f7acf6aa\'}\nipa-dnskeysync-replica: DEBUG new master keys in LDAP HSM: {\'0x3e0cafd58625e3490b7650028f979d02\'}\nTraceback (most recent call last):\n File "/usr/libexec/ipa/ipa-dnskeysync-replica", line 189, in <module>\n ldap2replica_master_keys_sync(ldapkeydb, localhsm)\n File "/usr/libexec/ipa/ipa-dnskeysync-replica", line 80, in ldap2replica_master_keys_sync\n str_hexlify(mkey_id)\nValueError: Master key 0x3e0cafd58625e3490b7650028f979d02 in LDAP is missing key material referenced by ipaSecretKeyRefObject attribute\n') Jan 10 08:50:27 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:50:27 hn-dlp systemd[1]: ipa-dnskeysyncd.service: Failed with result 'exit-code'. Jan 10 08:50:30 hn-dlp systemd[1]: httpd.service: Succeeded. Jan 10 08:50:30 hn-dlp systemd[1]: Stopped The Apache HTTP Server. Jan 10 08:50:30 hn-dlp systemd[1]: Starting One-time temporary TLS key generation for httpd.service... Jan 10 08:50:30 hn-dlp systemd[1]: httpd-init.service: Succeeded. Jan 10 08:50:30 hn-dlp systemd[1]: Started One-time temporary TLS key generation for httpd.service. Jan 10 08:50:30 hn-dlp systemd[1]: Starting The Apache HTTP Server... Jan 10 08:50:31 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[6647]: Kerberos authentication failed: Major (851968): Unspecified GSS failure. Minor code may provide more information, Minor (2529639107): No credentials cache found Jan 10 08:50:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:50:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:50:31 hn-dlp ipa-httpd-kdcproxy[6667]: ipa: INFO: KDC proxy enabled Jan 10 08:50:31 hn-dlp ipa-httpd-kdcproxy[6667]: ipa-httpd-kdcproxy: INFO KDC proxy enabled Jan 10 08:50:32 hn-dlp systemd[1]: Started The Apache HTTP Server. Jan 10 08:50:32 hn-dlp httpd[6674]: Server configured, listening on: port 443, port 80 Jan 10 08:50:32 hn-dlp systemd[1]: Stopped IPA key daemon. Jan 10 08:50:33 hn-dlp platform-python[6555]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:50:33 hn-dlp platform-python[6555]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:50:33 hn-dlp platform-python[6555]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:50:34 hn-dlp systemd[1]: Reloading. Jan 10 08:51:26 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:51:26.515177460 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=caToha-dlp.ipa.example.local" (ha-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 08:51:26 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:51:26.596521159 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=caTonf-dlp.ipa.example.local" (nf-dlp:389) - Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) () Jan 10 08:51:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:51:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 52. Jan 10 08:51:31 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:51:31 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:51:31 hn-dlp systemd[1]: Stopping IPA OpenDNSSEC Signer replacement... Jan 10 08:51:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Succeeded. Jan 10 08:51:31 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:51:31 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:51:31 hn-dlp systemd[1]: /usr/lib/systemd/system/ods-signerd.service:3: Failed to add dependency on ods-enforcerd, ignoring: Invalid argument Jan 10 08:51:32 hn-dlp systemd[1]: /usr/lib/systemd/system/ods-signerd.service:3: Failed to add dependency on ods-enforcerd, ignoring: Invalid argument Jan 10 08:51:32 hn-dlp systemd[1]: /usr/lib/systemd/system/ods-signerd.service:3: Failed to add dependency on ods-enforcerd, ignoring: Invalid argument Jan 10 08:51:32 hn-dlp systemd[1]: /usr/lib/systemd/system/ods-signerd.service:3: Failed to add dependency on ods-enforcerd, ignoring: Invalid argument Jan 10 08:51:32 hn-dlp systemd[1]: /usr/lib/systemd/system/ods-signerd.service:3: Failed to add dependency on ods-enforcerd, ignoring: Invalid argument Jan 10 08:51:32 hn-dlp systemd[1]: Reloading. Jan 10 08:51:32 hn-dlp systemd[1]: Reloading. Jan 10 08:51:32 hn-dlp platform-python[6555]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:51:32 hn-dlp platform-python[6555]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:51:32 hn-dlp platform-python[6555]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:51:33 hn-dlp systemd[1]: Starting OpenDNSSEC Enforcer daemon... Jan 10 08:51:33 hn-dlp ods-enforcerd[7548]: [engine] running as pid 7548 Jan 10 08:51:33 hn-dlp ods-enforcerd[7548]: [engine] enforcer started Jan 10 08:51:33 hn-dlp ods-enforcerd[7548]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:51:33 hn-dlp ods-enforcerd[7548]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:51:33 hn-dlp ods-enforcerd[7548]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:51:33 hn-dlp ods-enforcerd[7547]: OpenDNSSEC key and signing policy enforcer version 2.1.6 Jan 10 08:51:33 hn-dlp systemd[1]: Started OpenDNSSEC Enforcer daemon. Jan 10 08:51:33 hn-dlp ods-enforcerd[7548]: INFO: The XML in /etc/opendnssec/kasp.xml is valid Jan 10 08:51:33 hn-dlp ods-enforcerd[7548]: WARNING: In policy default, Y used in duration field for Keys/KSK Lifetime (P2Y) in /etc/opendnssec/kasp.xml - this will be interpreted as 365 days Jan 10 08:51:33 hn-dlp ods-enforcerd[7548]: [policy_import] policy default created Jan 10 08:51:33 hn-dlp systemd[1]: Reloading. Jan 10 08:51:33 hn-dlp systemd[1]: Started IPA key daemon. Jan 10 08:51:33 hn-dlp systemd[1]: Starting Generate rndc key for BIND (DNS)... Jan 10 08:51:33 hn-dlp systemd[1]: named-setup-rndc.service: Succeeded. Jan 10 08:51:33 hn-dlp systemd[1]: Started Generate rndc key for BIND (DNS). Jan 10 08:51:33 hn-dlp systemd[1]: Starting Berkeley Internet Name Domain (DNS) with native PKCS#11... Jan 10 08:51:33 hn-dlp bash[7592]: zone localhost.localdomain/IN: loaded serial 0 Jan 10 08:51:33 hn-dlp bash[7592]: zone localhost/IN: loaded serial 0 Jan 10 08:51:33 hn-dlp bash[7592]: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 0 Jan 10 08:51:33 hn-dlp bash[7592]: zone 1.0.0.127.in-addr.arpa/IN: loaded serial 0 Jan 10 08:51:33 hn-dlp bash[7592]: zone 0.in-addr.arpa/IN: loaded serial 0 Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: starting BIND 9.11.20-RedHat-9.11.20-5.el8 (Extended Support Version) <id:f3d1d66> Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: running on Linux x86_64 4.18.0-240.1.1.el8_3.x86_64 #1 SMP Thu Nov 19 17:20:08 UTC 2020 Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: built with '--build=x86_64-redhat-linux-gnu' '--host=x86_64-redhat-linux-gnu' '--program-prefix=' '--disable-dependency-tracking' '--prefix=/usr' '--exec-prefix=/usr' '--bindir=/usr/bin' '--sbindir=/usr/sbin' '--sysconfdir=/etc' '--datadir=/usr/share' '--includedir=/usr/include' '--libdir=/usr/lib64' '--libexecdir=/usr/libexec' '--sharedstatedir=/var/lib' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--with-python=/usr/libexec/platform-python' '--with-libtool' '--localstatedir=/var' '--enable-threads' '--enable-ipv6' '--enable-filter-aaaa' '--with-pic' '--disable-static' '--includedir=/usr/include/bind9' '--with-tuning=large' '--with-libidn2' '--enable-openssl-hash' '--with-geoip2' '--enable-native-pkcs11' '--with-pkcs11=/usr/lib64/pkcs11/libsofthsm2.so' '--with-dlopen=yes' '--with-dlz-ldap=yes' '--with-dlz-postgres=yes' '--with-dlz-mysql=yes' '--with-dlz-filesystem=yes' '--with-dlz-bdb=yes' '--with-gssapi=yes' '--disable-isc-spnego' '--with-lmdb=no' '--with-cmocka' '--enable-fixed-rrset' '--with-docbook-xsl=/usr/share/sgml/docbook/xsl-stylesheets' '--enable-full-report' 'build_alias=x86_64-redhat-linux-gnu' 'host_alias=x86_64-redhat-linux-gnu' 'CFLAGS= -O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection' 'LDFLAGS=-Wl,-z,relro -Wl,-z,now -specs=/usr/lib/rpm/redhat/redhat-hardened-ld' 'CPPFLAGS= -DDIG_SIGCHASE' 'PKG_CONFIG_PATH=:/usr/lib64/pkgconfig:/usr/share/pkgconfig' Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: running as: named-pkcs11 -u named -c /etc/named.conf Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: compiled by GCC 8.3.1 20191121 (Red Hat 8.3.1-5) Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: compiled with libxml2 version: 2.9.7 Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: linked to libxml2 version: 20907 Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: compiled with zlib version: 1.2.11 Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: linked to zlib version: 1.2.11 Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: threads support is enabled Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: ---------------------------------------------------- Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: BIND 9 is maintained by Internet Systems Consortium, Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: Inc. (ISC), a non-profit 501(c)(3) public-benefit Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: corporation. Support and training for BIND 9 are Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: available at https://www.isc.org/support Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: ---------------------------------------------------- Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: adjusted limit on open files from 262144 to 1048576 Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: found 4 CPUs, using 4 worker threads Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: using 3 UDP listeners per interface Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: using up to 21000 sockets Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:51:34 hn-dlp platform-python[7481]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: loading configuration from '/etc/named.conf' Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: unable to open '/etc/bind.keys'; using built-in keys instead Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: looking for GeoIP2 databases in '/usr/share/GeoIP' Jan 10 08:51:34 hn-dlp platform-python[7481]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:51:34 hn-dlp platform-python[7481]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-Country.mmdb' Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-City.mmdb' Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: using default UDP/IPv4 port range: [32768, 60999] Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: using default UDP/IPv6 port range: [32768, 60999] Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: listening on IPv6 interfaces, port 53 Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: listening on IPv4 interface lo, 127.0.0.1#53 Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: listening on IPv4 interface ens18, 172.19.187.2#53 Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: generating session key for dynamic DNS Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: sizing zone task pool based on 6 zones Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: none:104: 'max-cache-size 90%' - setting to 1180MB (out of 1312MB) Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: set up managed keys zone for view _default, file '/var/named/dynamic/managed-keys.bind' Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: loading DynDB instance 'ipa' driver '/usr/lib64/bind/ldap.so' Jan 10 08:51:34 hn-dlp named-pkcs11[7597]: bind-dyndb-ldap version 11.3 compiled at 16:06:42 Sep 1 2020, compiler 8.3.1 20191121 (Red Hat 8.3.1-5) Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 10.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 16.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 17.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 18.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 19.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 20.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 21.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 22.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 23.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 24.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 25.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 26.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 27.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 28.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 29.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 30.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 31.172.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 168.192.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 64.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 65.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 66.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 67.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 68.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 69.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 70.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 71.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 72.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 73.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 74.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 75.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 76.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 77.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 78.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 79.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 80.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 81.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 82.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 83.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 84.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 85.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 86.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 87.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 88.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 89.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 90.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 91.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 92.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 93.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 94.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 95.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 96.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 97.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 98.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 99.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 100.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 101.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 102.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 103.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 104.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 105.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 106.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 107.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 108.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 109.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 110.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 111.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 112.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 113.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 114.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 115.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 116.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 117.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 118.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 119.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 120.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 121.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 122.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 123.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 124.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 125.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 126.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 127.100.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 127.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 254.169.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 2.0.192.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 100.51.198.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 113.0.203.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 255.255.255.255.IN-ADDR.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: D.F.IP6.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 8.E.F.IP6.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 9.E.F.IP6.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: A.E.F.IP6.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: B.E.F.IP6.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: 8.B.D.0.1.0.0.2.IP6.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: EMPTY.AS112.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: automatic empty zone: HOME.ARPA Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: none:104: 'max-cache-size 90%' - setting to 1180MB (out of 1312MB) Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: configuring command channel from '/etc/rndc.key' Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: command channel listening on 127.0.0.1#953 Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: configuring command channel from '/etc/rndc.key' Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: command channel listening on ::1#953 Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: managed-keys-zone: journal file is out of date: removing journal file Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: managed-keys-zone: loaded serial 231 Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: shutting down automatic empty zones to enable forwarding for domain '.' Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone 115.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone 122.100.IN-ADDR.ARPA/IN: shutting down Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone 0.in-addr.arpa/IN: loaded serial 0 Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone 1.0.0.127.in-addr.arpa/IN: loaded serial 0 Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone 254.169.IN-ADDR.ARPA/IN: shutting down Jan 10 08:51:35 hn-dlp systemd[1]: Started Berkeley Internet Name Domain (DNS) with native PKCS#11. Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 0 Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone 113.0.203.IN-ADDR.ARPA/IN: shutting down Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone EMPTY.AS112.ARPA/IN: shutting down Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone localhost/IN: loaded serial 0 Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone localhost.localdomain/IN: loaded serial 0 Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: all zones loaded Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: running Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: LDAP configuration for instance 'ipa' synchronized Jan 10 08:51:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[7481]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: LDAP data for instance 'ipa' are being synchronized, please ignore message 'all zones loaded' Jan 10 08:51:35 hn-dlp ipa-ods-exporter[7481]: Traceback (most recent call last): Jan 10 08:51:35 hn-dlp ipa-ods-exporter[7481]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 08:51:35 hn-dlp ipa-ods-exporter[7481]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 08:51:35 hn-dlp ipa-ods-exporter[7481]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 08:51:35 hn-dlp ipa-ods-exporter[7481]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 08:51:35 hn-dlp ipa-ods-exporter[7481]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 08:51:35 hn-dlp ipa-ods-exporter[7481]: h = self.p11.import_public_key(**params) Jan 10 08:51:35 hn-dlp ipa-ods-exporter[7481]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 08:51:35 hn-dlp ipa-ods-exporter[7481]: raise DuplicationError("Public key with same ID already exists") Jan 10 08:51:35 hn-dlp ipa-ods-exporter[7481]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: forward zone 'int.example.local': loaded Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: managed-keys-zone: Key 20326 for zone . acceptance timer complete: key now trusted Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: forward zone 'srv.example.local': loaded Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone 177.19.172.in-addr.arpa/IN: loaded serial 1610265095 Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone 187.19.172.in-addr.arpa/IN: loaded serial 1610265095 Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone 195.19.172.in-addr.arpa/IN: loaded serial 1610265095 Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone 197.19.172.in-addr.arpa/IN: loaded serial 1610265095 Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone ipa.example.local/IN: loaded serial 1610265095 Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: 5 master zones from LDAP instance 'ipa' loaded (5 zones defined, 0 inactive, 0 failed to load) Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone 177.19.172.in-addr.arpa/IN: sending notifies (serial 1610265095) Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone 187.19.172.in-addr.arpa/IN: sending notifies (serial 1610265095) Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone ipa.example.local/IN: sending notifies (serial 1610265095) Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone 195.19.172.in-addr.arpa/IN: sending notifies (serial 1610265095) Jan 10 08:51:35 hn-dlp named-pkcs11[7597]: zone 197.19.172.in-addr.arpa/IN: sending notifies (serial 1610265095) Jan 10 08:51:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:51:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:51:39 hn-dlp ipa-dnskeysyncd[7581]: ipa-dnskeysyncd: INFO LDAP bind... Jan 10 08:51:39 hn-dlp ipa-dnskeysyncd[7581]: ipa-dnskeysyncd: INFO Commencing sync process Jan 10 08:51:39 hn-dlp ipa-dnskeysyncd[7581]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-eeae1a850283edc8a00566c3dee263f0,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:51:39 hn-dlp ipa-dnskeysyncd[7581]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c04eba886f71eaf6942e4187a168530d,cn=keys,idnsname=ipa.example.local.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone ipa.example.local. Jan 10 08:51:39 hn-dlp ipa-dnskeysyncd[7581]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-795ec7e363b4e831c99bc7751b006b8e,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:51:39 hn-dlp ipa-dnskeysyncd[7581]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-b16ee269a69c62ab190b78039c574e4b,cn=keys,idnsname=177.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 177.19.172.in-addr.arpa. Jan 10 08:51:39 hn-dlp ipa-dnskeysyncd[7581]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-c5b715f14457ccb40f60e224b2220d7f,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:51:39 hn-dlp ipa-dnskeysyncd[7581]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100003Z-6e817263927b3519a7b5757e90ba5cfc,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:51:39 hn-dlp ipa-dnskeysyncd[7581]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100539Z-49de8f2954963b5779491cdacc9232c5,cn=keys,idnsname=197.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 197.19.172.in-addr.arpa. Jan 10 08:51:39 hn-dlp ipa-dnskeysyncd[7581]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100002Z-3e7a2e5aaa81fd5f1608f7824dd42b8e,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:51:39 hn-dlp ipa-dnskeysyncd[7581]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100552Z-2ff98d67ad4fd9c22202c132ec0d4141,cn=keys,idnsname=187.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 187.19.172.in-addr.arpa. Jan 10 08:51:39 hn-dlp ipa-dnskeysyncd[7581]: ipaserver.dnssec.bindmgr: INFO Key metadata cn=KSK-20210101100556Z-708bc11ade0ce1fe2b4b061e80cc0035,cn=keys,idnsname=195.19.172.in-addr.arpa.,cn=dns,dc=ipa,dc=tecin,dc=net added to zone 195.19.172.in-addr.arpa. Jan 10 08:51:39 hn-dlp ipa-dnskeysyncd[7581]: ipaserver.dnssec.keysyncer: INFO Initial LDAP dump is done, sychronizing with ODS and BIND Jan 10 08:51:40 hn-dlp ods-enforcerd[7548]: INFO: The XML in /etc/opendnssec/zonelist.xml.new is valid Jan 10 08:51:40 hn-dlp ods-enforcerd[7548]: [zonelist_export_cmd] zonelist exported to /etc/opendnssec/zonelist.xml successfully Jan 10 08:51:40 hn-dlp ipa-dnskeysyncd[7581]: ipaserver.dnssec.odsmgr: INFO Zones removed from LDAP: [] Jan 10 08:51:40 hn-dlp ipa-dnskeysyncd[7581]: ipaserver.dnssec.odsmgr: INFO Zones added to LDAP: [] Jan 10 08:51:40 hn-dlp named-pkcs11[7597]: zone 177.19.172.in-addr.arpa/IN: sending notifies (serial 1610265095) Jan 10 08:51:40 hn-dlp named-pkcs11[7597]: zone 187.19.172.in-addr.arpa/IN: sending notifies (serial 1610265095) Jan 10 08:51:40 hn-dlp named-pkcs11[7597]: zone 195.19.172.in-addr.arpa/IN: sending notifies (serial 1610265095) Jan 10 08:51:43 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:51:45 hn-dlp systemd[1]: Starting Generate rndc key for BIND (DNS)... Jan 10 08:51:45 hn-dlp systemd[1]: named-setup-rndc.service: Succeeded. Jan 10 08:51:45 hn-dlp systemd[1]: Started Generate rndc key for BIND (DNS). Jan 10 08:51:45 hn-dlp systemd[1]: Starting One-time temporary TLS key generation for httpd.service... Jan 10 08:51:45 hn-dlp systemd[1]: httpd-init.service: Succeeded. Jan 10 08:51:45 hn-dlp systemd[1]: Started One-time temporary TLS key generation for httpd.service. Jan 10 08:52:36 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:52:36 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 1. Jan 10 08:52:36 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:52:36 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:52:44 hn-dlp platform-python[7668]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:52:45 hn-dlp platform-python[7668]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:52:45 hn-dlp platform-python[7668]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:52:45 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[7668]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:52:45 hn-dlp ipa-ods-exporter[7668]: Traceback (most recent call last): Jan 10 08:52:45 hn-dlp ipa-ods-exporter[7668]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 08:52:45 hn-dlp ipa-ods-exporter[7668]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 08:52:45 hn-dlp ipa-ods-exporter[7668]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 08:52:45 hn-dlp ipa-ods-exporter[7668]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 08:52:45 hn-dlp ipa-ods-exporter[7668]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 08:52:45 hn-dlp ipa-ods-exporter[7668]: h = self.p11.import_public_key(**params) Jan 10 08:52:45 hn-dlp ipa-ods-exporter[7668]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 08:52:45 hn-dlp ipa-ods-exporter[7668]: raise DuplicationError("Public key with same ID already exists") Jan 10 08:52:45 hn-dlp ipa-ods-exporter[7668]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 08:52:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:52:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:53:12 hn-dlp named-pkcs11[7597]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 08:53:12 hn-dlp named-pkcs11[7597]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:53:43 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:53:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:53:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 2. Jan 10 08:53:45 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:53:45 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:53:48 hn-dlp platform-python[7683]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:53:48 hn-dlp platform-python[7683]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:53:48 hn-dlp platform-python[7683]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:53:48 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[7683]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:53:48 hn-dlp ipa-ods-exporter[7683]: Traceback (most recent call last): Jan 10 08:53:48 hn-dlp ipa-ods-exporter[7683]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 08:53:48 hn-dlp ipa-ods-exporter[7683]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 08:53:48 hn-dlp ipa-ods-exporter[7683]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 08:53:48 hn-dlp ipa-ods-exporter[7683]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 08:53:48 hn-dlp ipa-ods-exporter[7683]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 08:53:48 hn-dlp ipa-ods-exporter[7683]: h = self.p11.import_public_key(**params) Jan 10 08:53:48 hn-dlp ipa-ods-exporter[7683]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 08:53:48 hn-dlp ipa-ods-exporter[7683]: raise DuplicationError("Public key with same ID already exists") Jan 10 08:53:48 hn-dlp ipa-ods-exporter[7683]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 08:53:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:53:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:54:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:54:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 3. Jan 10 08:54:48 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:54:48 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:54:51 hn-dlp platform-python[7692]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:54:51 hn-dlp platform-python[7692]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:54:51 hn-dlp platform-python[7692]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:54:51 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[7692]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:54:51 hn-dlp ipa-ods-exporter[7692]: Traceback (most recent call last): Jan 10 08:54:51 hn-dlp ipa-ods-exporter[7692]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 08:54:51 hn-dlp ipa-ods-exporter[7692]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 08:54:51 hn-dlp ipa-ods-exporter[7692]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 08:54:51 hn-dlp ipa-ods-exporter[7692]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 08:54:51 hn-dlp ipa-ods-exporter[7692]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 08:54:51 hn-dlp ipa-ods-exporter[7692]: h = self.p11.import_public_key(**params) Jan 10 08:54:51 hn-dlp ipa-ods-exporter[7692]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 08:54:51 hn-dlp ipa-ods-exporter[7692]: raise DuplicationError("Public key with same ID already exists") Jan 10 08:54:51 hn-dlp ipa-ods-exporter[7692]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 08:54:51 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:54:51 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:55:12 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:55:12 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:55:36 hn-dlp ns-slapd[5726]: [10/Jan/2021:08:55:36.040114569 +0100] - INFO - NSMMReplicationPlugin - bind_and_check_pwp - agmt="cn=caTonf-dlp.ipa.example.local" (nf-dlp:389): Replication bind with GSSAPI auth resumed Jan 10 08:55:43 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:55:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:55:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 4. Jan 10 08:55:52 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:55:52 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:55:54 hn-dlp platform-python[7700]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:55:54 hn-dlp platform-python[7700]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:55:54 hn-dlp platform-python[7700]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:55:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[7700]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:55:55 hn-dlp ipa-ods-exporter[7700]: Traceback (most recent call last): Jan 10 08:55:55 hn-dlp ipa-ods-exporter[7700]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 08:55:55 hn-dlp ipa-ods-exporter[7700]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 08:55:55 hn-dlp ipa-ods-exporter[7700]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 08:55:55 hn-dlp ipa-ods-exporter[7700]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 08:55:55 hn-dlp ipa-ods-exporter[7700]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 08:55:55 hn-dlp ipa-ods-exporter[7700]: h = self.p11.import_public_key(**params) Jan 10 08:55:55 hn-dlp ipa-ods-exporter[7700]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 08:55:55 hn-dlp ipa-ods-exporter[7700]: raise DuplicationError("Public key with same ID already exists") Jan 10 08:55:55 hn-dlp ipa-ods-exporter[7700]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 08:55:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:55:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:56:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:56:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 5. Jan 10 08:56:55 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:56:55 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:56:58 hn-dlp platform-python[7710]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:56:58 hn-dlp platform-python[7710]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:56:58 hn-dlp platform-python[7710]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:56:58 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[7710]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 08:56:58 hn-dlp ipa-ods-exporter[7710]: Traceback (most recent call last): Jan 10 08:56:58 hn-dlp ipa-ods-exporter[7710]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 08:56:58 hn-dlp ipa-ods-exporter[7710]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 08:56:58 hn-dlp ipa-ods-exporter[7710]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 08:56:58 hn-dlp ipa-ods-exporter[7710]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 08:56:58 hn-dlp ipa-ods-exporter[7710]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 08:56:58 hn-dlp ipa-ods-exporter[7710]: h = self.p11.import_public_key(**params) Jan 10 08:56:58 hn-dlp ipa-ods-exporter[7710]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 08:56:58 hn-dlp ipa-ods-exporter[7710]: raise DuplicationError("Public key with same ID already exists") Jan 10 08:56:58 hn-dlp ipa-ods-exporter[7710]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 08:56:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:56:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:57:12 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:57:12 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:57:29 hn-dlp kcm[6578]: Shutting down (status = 0) Jan 10 08:57:30 hn-dlp systemd[1]: sssd-kcm.service: Succeeded. Jan 10 08:57:44 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:57:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:57:58 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 6. Jan 10 08:57:58 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:57:58 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:58:01 hn-dlp platform-python[7720]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:58:01 hn-dlp platform-python[7720]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:58:01 hn-dlp platform-python[7720]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:58:01 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[7720]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 08:58:01 hn-dlp ipa-ods-exporter[7720]: Traceback (most recent call last): Jan 10 08:58:01 hn-dlp ipa-ods-exporter[7720]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 08:58:01 hn-dlp ipa-ods-exporter[7720]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 08:58:01 hn-dlp ipa-ods-exporter[7720]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 08:58:01 hn-dlp ipa-ods-exporter[7720]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 08:58:01 hn-dlp ipa-ods-exporter[7720]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 08:58:01 hn-dlp ipa-ods-exporter[7720]: h = self.p11.import_public_key(**params) Jan 10 08:58:01 hn-dlp ipa-ods-exporter[7720]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 08:58:01 hn-dlp ipa-ods-exporter[7720]: raise DuplicationError("Public key with same ID already exists") Jan 10 08:58:01 hn-dlp ipa-ods-exporter[7720]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 08:58:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:58:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:59:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 08:59:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 7. Jan 10 08:59:02 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 08:59:02 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 08:59:04 hn-dlp platform-python[7731]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 08:59:04 hn-dlp platform-python[7731]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 08:59:04 hn-dlp platform-python[7731]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 08:59:04 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[7731]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 08:59:04 hn-dlp ipa-ods-exporter[7731]: Traceback (most recent call last): Jan 10 08:59:04 hn-dlp ipa-ods-exporter[7731]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 08:59:04 hn-dlp ipa-ods-exporter[7731]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 08:59:04 hn-dlp ipa-ods-exporter[7731]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 08:59:04 hn-dlp ipa-ods-exporter[7731]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 08:59:04 hn-dlp ipa-ods-exporter[7731]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 08:59:04 hn-dlp ipa-ods-exporter[7731]: h = self.p11.import_public_key(**params) Jan 10 08:59:04 hn-dlp ipa-ods-exporter[7731]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 08:59:04 hn-dlp ipa-ods-exporter[7731]: raise DuplicationError("Public key with same ID already exists") Jan 10 08:59:04 hn-dlp ipa-ods-exporter[7731]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 08:59:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 08:59:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 08:59:12 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 08:59:12 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 08:59:44 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 08:59:57 hn-dlp named-pkcs11[7597]: client @0x7f6068005320 172.19.186.212#63796 (187.19.172.in-addr.arpa): transfer of '187.19.172.in-addr.arpa/IN': AXFR-style IXFR started (serial 1610265095) Jan 10 08:59:57 hn-dlp named-pkcs11[7597]: client @0x7f6068005320 172.19.186.212#63796 (187.19.172.in-addr.arpa): transfer of '187.19.172.in-addr.arpa/IN': AXFR-style IXFR ended Jan 10 08:59:57 hn-dlp named-pkcs11[7597]: client @0x7f6079884820 172.19.186.212#63797 (197.19.172.in-addr.arpa): transfer of '197.19.172.in-addr.arpa/IN': AXFR-style IXFR started (serial 1610265095) Jan 10 08:59:57 hn-dlp named-pkcs11[7597]: client @0x7f6079884820 172.19.186.212#63797 (197.19.172.in-addr.arpa): transfer of '197.19.172.in-addr.arpa/IN': AXFR-style IXFR ended Jan 10 08:59:57 hn-dlp named-pkcs11[7597]: client @0x7f6078118410 172.19.186.212#63795 (ipa.example.local): transfer of 'ipa.example.local/IN': AXFR-style IXFR started (serial 1610265095) Jan 10 08:59:57 hn-dlp named-pkcs11[7597]: client @0x7f6078118410 172.19.186.212#63795 (ipa.example.local): transfer of 'ipa.example.local/IN': AXFR-style IXFR ended Jan 10 08:59:57 hn-dlp named-pkcs11[7597]: client @0x7f6078126fe0 172.19.186.212#63794 (177.19.172.in-addr.arpa): transfer of '177.19.172.in-addr.arpa/IN': AXFR-style IXFR started (serial 1610265095) Jan 10 08:59:57 hn-dlp named-pkcs11[7597]: client @0x7f6078126fe0 172.19.186.212#63794 (177.19.172.in-addr.arpa): transfer of '177.19.172.in-addr.arpa/IN': AXFR-style IXFR ended Jan 10 09:00:00 hn-dlp named-pkcs11[7597]: no valid RRSIG resolving '168.192.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 09:00:00 hn-dlp named-pkcs11[7597]: no valid DS resolving '2.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:00 hn-dlp named-pkcs11[7597]: validating 4.133.168.192.in-addr.arpa/PTR: bad cache hit (168.192.in-addr.arpa/DS) Jan 10 09:00:00 hn-dlp named-pkcs11[7597]: broken trust chain resolving '4.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:00 hn-dlp named-pkcs11[7597]: validating 3.133.168.192.in-addr.arpa/PTR: bad cache hit (168.192.in-addr.arpa/DS) Jan 10 09:00:00 hn-dlp named-pkcs11[7597]: broken trust chain resolving '3.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:02 hn-dlp named-pkcs11[7597]: validating 104.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:02 hn-dlp named-pkcs11[7597]: broken trust chain resolving '104.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:02 hn-dlp named-pkcs11[7597]: validating 109.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:02 hn-dlp named-pkcs11[7597]: broken trust chain resolving '109.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:02 hn-dlp named-pkcs11[7597]: validating 110.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:02 hn-dlp named-pkcs11[7597]: broken trust chain resolving '110.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:02 hn-dlp named-pkcs11[7597]: validating 113.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:02 hn-dlp named-pkcs11[7597]: broken trust chain resolving '113.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:02 hn-dlp named-pkcs11[7597]: validating 191.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:02 hn-dlp named-pkcs11[7597]: broken trust chain resolving '191.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 192.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '192.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 203.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '203.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 254.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '254.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 104.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '104.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 171.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '171.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 173.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '173.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 183.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '183.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 204.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '204.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 213.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '213.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 216.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '216.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 217.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '217.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 1.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 5.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '5.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 14.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '14.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 15.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '15.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 1.171.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.171.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 2.171.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '2.171.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 100.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '100.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 103.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '103.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 254.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '254.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 104.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '104.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 107.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '107.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 254.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '254.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 5.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '5.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 11.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '11.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: validating 100.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '100.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:04 hn-dlp named-pkcs11[7597]: validating 254.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:00:04 hn-dlp named-pkcs11[7597]: broken trust chain resolving '254.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:00:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:00:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 8. Jan 10 09:00:05 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:00:05 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:00:07 hn-dlp platform-python[7741]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:00:07 hn-dlp platform-python[7741]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:00:07 hn-dlp platform-python[7741]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:00:08 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[7741]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:00:08 hn-dlp ipa-ods-exporter[7741]: Traceback (most recent call last): Jan 10 09:00:08 hn-dlp ipa-ods-exporter[7741]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:00:08 hn-dlp ipa-ods-exporter[7741]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:00:08 hn-dlp ipa-ods-exporter[7741]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:00:08 hn-dlp ipa-ods-exporter[7741]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:00:08 hn-dlp ipa-ods-exporter[7741]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:00:08 hn-dlp ipa-ods-exporter[7741]: h = self.p11.import_public_key(**params) Jan 10 09:00:08 hn-dlp ipa-ods-exporter[7741]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:00:08 hn-dlp ipa-ods-exporter[7741]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:00:08 hn-dlp ipa-ods-exporter[7741]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:00:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:00:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:00:31 hn-dlp systemd[1]: Created slice User Slice of UID 2002. Jan 10 09:00:31 hn-dlp systemd[1]: Started /run/user/2002 mount wrapper. Jan 10 09:00:31 hn-dlp systemd[1]: Starting User Manager for UID 2002... Jan 10 09:00:31 hn-dlp systemd-logind[744]: New session 8 of user svcforeman. Jan 10 09:00:31 hn-dlp systemd[1]: Started Session 8 of user svcforeman. Jan 10 09:00:32 hn-dlp systemd[7754]: Started Mark boot as successful after the user session has run 2 minutes. Jan 10 09:00:32 hn-dlp systemd[7754]: Reached target Timers. Jan 10 09:00:32 hn-dlp systemd[7754]: Starting D-Bus User Message Bus Socket. Jan 10 09:00:32 hn-dlp systemd[7754]: Reached target Paths. Jan 10 09:00:32 hn-dlp systemd[7754]: Listening on D-Bus User Message Bus Socket. Jan 10 09:00:32 hn-dlp systemd[7754]: Reached target Sockets. Jan 10 09:00:32 hn-dlp systemd[7754]: Reached target Basic System. Jan 10 09:00:32 hn-dlp systemd[7754]: Reached target Default. Jan 10 09:00:32 hn-dlp systemd[7754]: Startup finished in 126ms. Jan 10 09:00:32 hn-dlp systemd[1]: Started User Manager for UID 2002. Jan 10 09:00:34 hn-dlp platform-python[7915]: ansible-setup Invoked with gather_timeout=10 gather_subset=['all'] filter=* fact_path=/etc/ansible/facts.d Jan 10 09:01:05 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.48' (uid=0 pid=677 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 09:01:05 hn-dlp dbus-daemon[8100]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 09:01:08 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 09:01:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:01:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 9. Jan 10 09:01:08 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:01:08 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:01:09 hn-dlp setroubleshoot[8100]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der Jan 10 09:01:09 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.316' (uid=995 pid=8100 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 09:01:09 hn-dlp dbus-daemon[8114]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 09:01:12 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:01:12 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:01:13 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 09:01:20 hn-dlp setroubleshoot[8100]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 09:01:20 hn-dlp setroubleshoot[8100]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-090000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 09:01:21 hn-dlp platform-python[8103]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:01:21 hn-dlp platform-python[8103]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:01:21 hn-dlp platform-python[8103]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:01:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8103]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:01:22 hn-dlp ipa-ods-exporter[8103]: Traceback (most recent call last): Jan 10 09:01:22 hn-dlp ipa-ods-exporter[8103]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:01:22 hn-dlp ipa-ods-exporter[8103]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:01:22 hn-dlp ipa-ods-exporter[8103]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:01:22 hn-dlp ipa-ods-exporter[8103]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:01:22 hn-dlp ipa-ods-exporter[8103]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:01:22 hn-dlp ipa-ods-exporter[8103]: h = self.p11.import_public_key(**params) Jan 10 09:01:22 hn-dlp ipa-ods-exporter[8103]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:01:22 hn-dlp ipa-ods-exporter[8103]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:01:22 hn-dlp ipa-ods-exporter[8103]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:01:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:01:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:01:41 hn-dlp systemd[1]: session-8.scope: Succeeded. Jan 10 09:01:41 hn-dlp systemd-logind[744]: Session 8 logged out. Waiting for processes to exit. Jan 10 09:01:41 hn-dlp systemd-logind[744]: Removed session 8. Jan 10 09:01:41 hn-dlp systemd[1]: Stopping User Manager for UID 2002... Jan 10 09:01:41 hn-dlp systemd[7754]: Stopped target Default. Jan 10 09:01:41 hn-dlp systemd[7754]: Stopped target Basic System. Jan 10 09:01:41 hn-dlp systemd[7754]: Stopped target Sockets. Jan 10 09:01:41 hn-dlp systemd[7754]: dbus.socket: Succeeded. Jan 10 09:01:41 hn-dlp systemd[7754]: Closed D-Bus User Message Bus Socket. Jan 10 09:01:41 hn-dlp systemd[7754]: Stopped target Paths. Jan 10 09:01:41 hn-dlp systemd[7754]: Stopped target Timers. Jan 10 09:01:41 hn-dlp systemd[7754]: grub-boot-success.timer: Succeeded. Jan 10 09:01:41 hn-dlp systemd[7754]: Stopped Mark boot as successful after the user session has run 2 minutes. Jan 10 09:01:41 hn-dlp systemd[7754]: Reached target Shutdown. Jan 10 09:01:41 hn-dlp systemd[7754]: Starting Exit the Session... Jan 10 09:01:41 hn-dlp systemd[1]: user@2002.service: Succeeded. Jan 10 09:01:41 hn-dlp systemd[1]: Stopped User Manager for UID 2002. Jan 10 09:01:41 hn-dlp systemd[1]: Stopping /run/user/2002 mount wrapper... Jan 10 09:01:41 hn-dlp systemd[1]: Removed slice User Slice of UID 2002. Jan 10 09:01:41 hn-dlp systemd[2804]: run-user-2002.mount: Succeeded. Jan 10 09:01:41 hn-dlp systemd[1]: run-user-2002.mount: Succeeded. Jan 10 09:01:41 hn-dlp systemd[1]: user-runtime-dir@2002.service: Succeeded. Jan 10 09:01:41 hn-dlp systemd[1]: Stopped /run/user/2002 mount wrapper. Jan 10 09:01:45 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:02:13 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.48' (uid=0 pid=677 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 09:02:13 hn-dlp dbus-daemon[8136]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 09:02:17 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 09:02:17 hn-dlp setroubleshoot[8136]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der Jan 10 09:02:18 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.322' (uid=995 pid=8136 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 09:02:18 hn-dlp dbus-daemon[8149]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 09:02:18 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 09:02:21 hn-dlp setroubleshoot[8136]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 09:02:21 hn-dlp setroubleshoot[8136]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-090000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 09:02:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:02:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 10. Jan 10 09:02:23 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:02:23 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:02:30 hn-dlp platform-python[8154]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:02:30 hn-dlp platform-python[8154]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:02:30 hn-dlp platform-python[8154]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:02:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8154]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:02:30 hn-dlp ipa-ods-exporter[8154]: Traceback (most recent call last): Jan 10 09:02:30 hn-dlp ipa-ods-exporter[8154]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:02:30 hn-dlp ipa-ods-exporter[8154]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:02:30 hn-dlp ipa-ods-exporter[8154]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:02:30 hn-dlp ipa-ods-exporter[8154]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:02:30 hn-dlp ipa-ods-exporter[8154]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:02:30 hn-dlp ipa-ods-exporter[8154]: h = self.p11.import_public_key(**params) Jan 10 09:02:30 hn-dlp ipa-ods-exporter[8154]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:02:30 hn-dlp ipa-ods-exporter[8154]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:02:30 hn-dlp ipa-ods-exporter[8154]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:02:30 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:02:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:03:01 hn-dlp systemd[1]: Starting dnf makecache... Jan 10 09:03:04 hn-dlp dnf[8164]: Updating Subscription Management repositories. Jan 10 09:03:05 hn-dlp dnf[8164]: Metadata cache refreshed recently. Jan 10 09:03:05 hn-dlp systemd[1]: dnf-makecache.service: Succeeded. Jan 10 09:03:05 hn-dlp systemd[1]: Started dnf makecache. Jan 10 09:03:12 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:03:12 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:03:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:03:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 11. Jan 10 09:03:31 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:03:31 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:03:34 hn-dlp platform-python[8170]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:03:34 hn-dlp platform-python[8170]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:03:34 hn-dlp platform-python[8170]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:03:34 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8170]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:03:34 hn-dlp ipa-ods-exporter[8170]: Traceback (most recent call last): Jan 10 09:03:34 hn-dlp ipa-ods-exporter[8170]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:03:34 hn-dlp ipa-ods-exporter[8170]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:03:34 hn-dlp ipa-ods-exporter[8170]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:03:34 hn-dlp ipa-ods-exporter[8170]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:03:34 hn-dlp ipa-ods-exporter[8170]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:03:34 hn-dlp ipa-ods-exporter[8170]: h = self.p11.import_public_key(**params) Jan 10 09:03:34 hn-dlp ipa-ods-exporter[8170]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:03:34 hn-dlp ipa-ods-exporter[8170]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:03:34 hn-dlp ipa-ods-exporter[8170]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:03:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:03:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:03:45 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:04:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:04:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 12. Jan 10 09:04:34 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:04:34 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:04:37 hn-dlp platform-python[8179]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:04:37 hn-dlp platform-python[8179]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:04:37 hn-dlp platform-python[8179]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:04:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8179]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:04:37 hn-dlp ipa-ods-exporter[8179]: Traceback (most recent call last): Jan 10 09:04:37 hn-dlp ipa-ods-exporter[8179]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:04:37 hn-dlp ipa-ods-exporter[8179]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:04:37 hn-dlp ipa-ods-exporter[8179]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:04:37 hn-dlp ipa-ods-exporter[8179]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:04:37 hn-dlp ipa-ods-exporter[8179]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:04:37 hn-dlp ipa-ods-exporter[8179]: h = self.p11.import_public_key(**params) Jan 10 09:04:37 hn-dlp ipa-ods-exporter[8179]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:04:37 hn-dlp ipa-ods-exporter[8179]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:04:37 hn-dlp ipa-ods-exporter[8179]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:04:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:04:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:05:12 hn-dlp named-pkcs11[7597]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 09:05:12 hn-dlp named-pkcs11[7597]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:05:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:05:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 13. Jan 10 09:05:37 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:05:37 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:05:40 hn-dlp platform-python[8188]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:05:40 hn-dlp platform-python[8188]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:05:40 hn-dlp platform-python[8188]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:05:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8188]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:05:40 hn-dlp ipa-ods-exporter[8188]: Traceback (most recent call last): Jan 10 09:05:40 hn-dlp ipa-ods-exporter[8188]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:05:40 hn-dlp ipa-ods-exporter[8188]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:05:40 hn-dlp ipa-ods-exporter[8188]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:05:40 hn-dlp ipa-ods-exporter[8188]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:05:40 hn-dlp ipa-ods-exporter[8188]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:05:40 hn-dlp ipa-ods-exporter[8188]: h = self.p11.import_public_key(**params) Jan 10 09:05:40 hn-dlp ipa-ods-exporter[8188]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:05:40 hn-dlp ipa-ods-exporter[8188]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:05:40 hn-dlp ipa-ods-exporter[8188]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:05:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:05:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:05:45 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:06:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:06:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 14. Jan 10 09:06:40 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:06:40 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:06:43 hn-dlp platform-python[8197]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:06:43 hn-dlp platform-python[8197]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:06:43 hn-dlp platform-python[8197]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:06:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8197]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:06:43 hn-dlp ipa-ods-exporter[8197]: Traceback (most recent call last): Jan 10 09:06:43 hn-dlp ipa-ods-exporter[8197]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:06:43 hn-dlp ipa-ods-exporter[8197]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:06:43 hn-dlp ipa-ods-exporter[8197]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:06:43 hn-dlp ipa-ods-exporter[8197]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:06:43 hn-dlp ipa-ods-exporter[8197]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:06:43 hn-dlp ipa-ods-exporter[8197]: h = self.p11.import_public_key(**params) Jan 10 09:06:43 hn-dlp ipa-ods-exporter[8197]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:06:43 hn-dlp ipa-ods-exporter[8197]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:06:43 hn-dlp ipa-ods-exporter[8197]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:06:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:06:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:07:12 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:07:12 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:07:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:07:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 15. Jan 10 09:07:43 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:07:43 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:07:46 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:07:46 hn-dlp platform-python[8208]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:07:46 hn-dlp platform-python[8208]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:07:46 hn-dlp platform-python[8208]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:07:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8208]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:07:46 hn-dlp ipa-ods-exporter[8208]: Traceback (most recent call last): Jan 10 09:07:46 hn-dlp ipa-ods-exporter[8208]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:07:46 hn-dlp ipa-ods-exporter[8208]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:07:46 hn-dlp ipa-ods-exporter[8208]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:07:46 hn-dlp ipa-ods-exporter[8208]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:07:46 hn-dlp ipa-ods-exporter[8208]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:07:46 hn-dlp ipa-ods-exporter[8208]: h = self.p11.import_public_key(**params) Jan 10 09:07:46 hn-dlp ipa-ods-exporter[8208]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:07:46 hn-dlp ipa-ods-exporter[8208]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:07:46 hn-dlp ipa-ods-exporter[8208]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:07:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:07:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:08:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:08:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 16. Jan 10 09:08:47 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:08:47 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:08:49 hn-dlp platform-python[8218]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:08:49 hn-dlp platform-python[8218]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:08:49 hn-dlp platform-python[8218]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:08:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8218]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:08:49 hn-dlp ipa-ods-exporter[8218]: Traceback (most recent call last): Jan 10 09:08:49 hn-dlp ipa-ods-exporter[8218]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:08:49 hn-dlp ipa-ods-exporter[8218]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:08:49 hn-dlp ipa-ods-exporter[8218]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:08:49 hn-dlp ipa-ods-exporter[8218]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:08:49 hn-dlp ipa-ods-exporter[8218]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:08:49 hn-dlp ipa-ods-exporter[8218]: h = self.p11.import_public_key(**params) Jan 10 09:08:49 hn-dlp ipa-ods-exporter[8218]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:08:49 hn-dlp ipa-ods-exporter[8218]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:08:49 hn-dlp ipa-ods-exporter[8218]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:08:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:08:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:09:12 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:09:12 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:09:46 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:09:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:09:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 17. Jan 10 09:09:50 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:09:50 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:09:52 hn-dlp platform-python[8228]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:09:52 hn-dlp platform-python[8228]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:09:52 hn-dlp platform-python[8228]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:09:53 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8228]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:09:53 hn-dlp ipa-ods-exporter[8228]: Traceback (most recent call last): Jan 10 09:09:53 hn-dlp ipa-ods-exporter[8228]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:09:53 hn-dlp ipa-ods-exporter[8228]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:09:53 hn-dlp ipa-ods-exporter[8228]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:09:53 hn-dlp ipa-ods-exporter[8228]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:09:53 hn-dlp ipa-ods-exporter[8228]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:09:53 hn-dlp ipa-ods-exporter[8228]: h = self.p11.import_public_key(**params) Jan 10 09:09:53 hn-dlp ipa-ods-exporter[8228]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:09:53 hn-dlp ipa-ods-exporter[8228]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:09:53 hn-dlp ipa-ods-exporter[8228]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:09:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:09:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:10:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:10:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 18. Jan 10 09:10:53 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:10:53 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:10:55 hn-dlp platform-python[8236]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:10:55 hn-dlp platform-python[8236]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:10:55 hn-dlp platform-python[8236]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:10:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8236]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:10:56 hn-dlp ipa-ods-exporter[8236]: Traceback (most recent call last): Jan 10 09:10:56 hn-dlp ipa-ods-exporter[8236]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:10:56 hn-dlp ipa-ods-exporter[8236]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:10:56 hn-dlp ipa-ods-exporter[8236]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:10:56 hn-dlp ipa-ods-exporter[8236]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:10:56 hn-dlp ipa-ods-exporter[8236]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:10:56 hn-dlp ipa-ods-exporter[8236]: h = self.p11.import_public_key(**params) Jan 10 09:10:56 hn-dlp ipa-ods-exporter[8236]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:10:56 hn-dlp ipa-ods-exporter[8236]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:10:56 hn-dlp ipa-ods-exporter[8236]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:10:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:10:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:11:12 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:11:12 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:11:46 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:11:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:11:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 19. Jan 10 09:11:56 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:11:56 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:11:58 hn-dlp platform-python[8245]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:11:58 hn-dlp platform-python[8245]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:11:58 hn-dlp platform-python[8245]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:11:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8245]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:11:59 hn-dlp ipa-ods-exporter[8245]: Traceback (most recent call last): Jan 10 09:11:59 hn-dlp ipa-ods-exporter[8245]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:11:59 hn-dlp ipa-ods-exporter[8245]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:11:59 hn-dlp ipa-ods-exporter[8245]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:11:59 hn-dlp ipa-ods-exporter[8245]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:11:59 hn-dlp ipa-ods-exporter[8245]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:11:59 hn-dlp ipa-ods-exporter[8245]: h = self.p11.import_public_key(**params) Jan 10 09:11:59 hn-dlp ipa-ods-exporter[8245]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:11:59 hn-dlp ipa-ods-exporter[8245]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:11:59 hn-dlp ipa-ods-exporter[8245]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:11:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:11:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:12:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:12:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 20. Jan 10 09:12:59 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:12:59 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:13:02 hn-dlp platform-python[8255]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:13:02 hn-dlp platform-python[8255]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:13:02 hn-dlp platform-python[8255]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:13:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8255]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:13:02 hn-dlp ipa-ods-exporter[8255]: Traceback (most recent call last): Jan 10 09:13:02 hn-dlp ipa-ods-exporter[8255]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:13:02 hn-dlp ipa-ods-exporter[8255]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:13:02 hn-dlp ipa-ods-exporter[8255]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:13:02 hn-dlp ipa-ods-exporter[8255]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:13:02 hn-dlp ipa-ods-exporter[8255]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:13:02 hn-dlp ipa-ods-exporter[8255]: h = self.p11.import_public_key(**params) Jan 10 09:13:02 hn-dlp ipa-ods-exporter[8255]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:13:02 hn-dlp ipa-ods-exporter[8255]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:13:02 hn-dlp ipa-ods-exporter[8255]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:13:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:13:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:13:12 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:13:12 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:13:46 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:14:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:14:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 21. Jan 10 09:14:02 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:14:02 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:14:05 hn-dlp platform-python[8265]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:14:05 hn-dlp platform-python[8265]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:14:05 hn-dlp platform-python[8265]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:14:05 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8265]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:14:05 hn-dlp ipa-ods-exporter[8265]: Traceback (most recent call last): Jan 10 09:14:05 hn-dlp ipa-ods-exporter[8265]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:14:05 hn-dlp ipa-ods-exporter[8265]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:14:05 hn-dlp ipa-ods-exporter[8265]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:14:05 hn-dlp ipa-ods-exporter[8265]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:14:05 hn-dlp ipa-ods-exporter[8265]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:14:05 hn-dlp ipa-ods-exporter[8265]: h = self.p11.import_public_key(**params) Jan 10 09:14:05 hn-dlp ipa-ods-exporter[8265]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:14:05 hn-dlp ipa-ods-exporter[8265]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:14:05 hn-dlp ipa-ods-exporter[8265]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:14:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:14:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:15:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:15:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 22. Jan 10 09:15:05 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:15:05 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:15:08 hn-dlp platform-python[8273]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:15:08 hn-dlp platform-python[8273]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:15:08 hn-dlp platform-python[8273]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:15:08 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8273]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:15:08 hn-dlp ipa-ods-exporter[8273]: Traceback (most recent call last): Jan 10 09:15:08 hn-dlp ipa-ods-exporter[8273]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:15:08 hn-dlp ipa-ods-exporter[8273]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:15:08 hn-dlp ipa-ods-exporter[8273]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:15:08 hn-dlp ipa-ods-exporter[8273]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:15:08 hn-dlp ipa-ods-exporter[8273]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:15:08 hn-dlp ipa-ods-exporter[8273]: h = self.p11.import_public_key(**params) Jan 10 09:15:08 hn-dlp ipa-ods-exporter[8273]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:15:08 hn-dlp ipa-ods-exporter[8273]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:15:08 hn-dlp ipa-ods-exporter[8273]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:15:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:15:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:15:12 hn-dlp named-pkcs11[7597]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 09:15:12 hn-dlp named-pkcs11[7597]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:15:47 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:16:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:16:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 23. Jan 10 09:16:09 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:16:09 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:16:11 hn-dlp platform-python[8281]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:16:11 hn-dlp platform-python[8281]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:16:11 hn-dlp platform-python[8281]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:16:11 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8281]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:16:11 hn-dlp ipa-ods-exporter[8281]: Traceback (most recent call last): Jan 10 09:16:11 hn-dlp ipa-ods-exporter[8281]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:16:11 hn-dlp ipa-ods-exporter[8281]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:16:11 hn-dlp ipa-ods-exporter[8281]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:16:11 hn-dlp ipa-ods-exporter[8281]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:16:11 hn-dlp ipa-ods-exporter[8281]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:16:11 hn-dlp ipa-ods-exporter[8281]: h = self.p11.import_public_key(**params) Jan 10 09:16:11 hn-dlp ipa-ods-exporter[8281]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:16:11 hn-dlp ipa-ods-exporter[8281]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:16:11 hn-dlp ipa-ods-exporter[8281]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:16:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:16:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:17:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:17:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 24. Jan 10 09:17:12 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:17:12 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:17:13 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:17:13 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:17:14 hn-dlp platform-python[8290]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:17:14 hn-dlp platform-python[8290]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:17:14 hn-dlp platform-python[8290]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:17:15 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8290]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:17:15 hn-dlp ipa-ods-exporter[8290]: Traceback (most recent call last): Jan 10 09:17:15 hn-dlp ipa-ods-exporter[8290]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:17:15 hn-dlp ipa-ods-exporter[8290]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:17:15 hn-dlp ipa-ods-exporter[8290]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:17:15 hn-dlp ipa-ods-exporter[8290]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:17:15 hn-dlp ipa-ods-exporter[8290]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:17:15 hn-dlp ipa-ods-exporter[8290]: h = self.p11.import_public_key(**params) Jan 10 09:17:15 hn-dlp ipa-ods-exporter[8290]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:17:15 hn-dlp ipa-ods-exporter[8290]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:17:15 hn-dlp ipa-ods-exporter[8290]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:17:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:17:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:17:47 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:18:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:18:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 25. Jan 10 09:18:15 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:18:15 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:18:18 hn-dlp platform-python[8301]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:18:18 hn-dlp platform-python[8301]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:18:18 hn-dlp platform-python[8301]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:18:18 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8301]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:18:18 hn-dlp ipa-ods-exporter[8301]: Traceback (most recent call last): Jan 10 09:18:18 hn-dlp ipa-ods-exporter[8301]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:18:18 hn-dlp ipa-ods-exporter[8301]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:18:18 hn-dlp ipa-ods-exporter[8301]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:18:18 hn-dlp ipa-ods-exporter[8301]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:18:18 hn-dlp ipa-ods-exporter[8301]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:18:18 hn-dlp ipa-ods-exporter[8301]: h = self.p11.import_public_key(**params) Jan 10 09:18:18 hn-dlp ipa-ods-exporter[8301]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:18:18 hn-dlp ipa-ods-exporter[8301]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:18:18 hn-dlp ipa-ods-exporter[8301]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:18:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:18:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:19:14 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:19:14 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:19:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:19:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 26. Jan 10 09:19:18 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:19:18 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:19:21 hn-dlp platform-python[8311]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:19:21 hn-dlp platform-python[8311]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:19:21 hn-dlp platform-python[8311]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:19:21 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8311]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:19:21 hn-dlp ipa-ods-exporter[8311]: Traceback (most recent call last): Jan 10 09:19:21 hn-dlp ipa-ods-exporter[8311]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:19:21 hn-dlp ipa-ods-exporter[8311]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:19:21 hn-dlp ipa-ods-exporter[8311]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:19:21 hn-dlp ipa-ods-exporter[8311]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:19:21 hn-dlp ipa-ods-exporter[8311]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:19:21 hn-dlp ipa-ods-exporter[8311]: h = self.p11.import_public_key(**params) Jan 10 09:19:21 hn-dlp ipa-ods-exporter[8311]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:19:21 hn-dlp ipa-ods-exporter[8311]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:19:21 hn-dlp ipa-ods-exporter[8311]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:19:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:19:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:19:47 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:20:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:20:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 27. Jan 10 09:20:22 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:20:22 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:20:24 hn-dlp platform-python[8322]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:20:24 hn-dlp platform-python[8322]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:20:24 hn-dlp platform-python[8322]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:20:24 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8322]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:20:24 hn-dlp ipa-ods-exporter[8322]: Traceback (most recent call last): Jan 10 09:20:24 hn-dlp ipa-ods-exporter[8322]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:20:24 hn-dlp ipa-ods-exporter[8322]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:20:24 hn-dlp ipa-ods-exporter[8322]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:20:24 hn-dlp ipa-ods-exporter[8322]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:20:24 hn-dlp ipa-ods-exporter[8322]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:20:24 hn-dlp ipa-ods-exporter[8322]: h = self.p11.import_public_key(**params) Jan 10 09:20:24 hn-dlp ipa-ods-exporter[8322]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:20:24 hn-dlp ipa-ods-exporter[8322]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:20:24 hn-dlp ipa-ods-exporter[8322]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:20:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:20:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:21:14 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:21:14 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:21:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:21:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 28. Jan 10 09:21:25 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:21:25 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:21:27 hn-dlp platform-python[8330]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:21:27 hn-dlp platform-python[8330]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:21:27 hn-dlp platform-python[8330]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:21:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8330]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:21:27 hn-dlp ipa-ods-exporter[8330]: Traceback (most recent call last): Jan 10 09:21:27 hn-dlp ipa-ods-exporter[8330]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:21:27 hn-dlp ipa-ods-exporter[8330]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:21:27 hn-dlp ipa-ods-exporter[8330]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:21:27 hn-dlp ipa-ods-exporter[8330]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:21:27 hn-dlp ipa-ods-exporter[8330]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:21:27 hn-dlp ipa-ods-exporter[8330]: h = self.p11.import_public_key(**params) Jan 10 09:21:27 hn-dlp ipa-ods-exporter[8330]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:21:27 hn-dlp ipa-ods-exporter[8330]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:21:27 hn-dlp ipa-ods-exporter[8330]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:21:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:21:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:21:47 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:22:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:22:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 29. Jan 10 09:22:28 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:22:28 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:22:30 hn-dlp platform-python[8339]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:22:30 hn-dlp platform-python[8339]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:22:30 hn-dlp platform-python[8339]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:22:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8339]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:22:30 hn-dlp ipa-ods-exporter[8339]: Traceback (most recent call last): Jan 10 09:22:30 hn-dlp ipa-ods-exporter[8339]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:22:30 hn-dlp ipa-ods-exporter[8339]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:22:30 hn-dlp ipa-ods-exporter[8339]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:22:30 hn-dlp ipa-ods-exporter[8339]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:22:30 hn-dlp ipa-ods-exporter[8339]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:22:30 hn-dlp ipa-ods-exporter[8339]: h = self.p11.import_public_key(**params) Jan 10 09:22:30 hn-dlp ipa-ods-exporter[8339]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:22:30 hn-dlp ipa-ods-exporter[8339]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:22:30 hn-dlp ipa-ods-exporter[8339]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:22:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:22:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:23:14 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:23:14 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:23:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:23:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 30. Jan 10 09:23:31 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:23:31 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:23:33 hn-dlp platform-python[8348]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:23:33 hn-dlp platform-python[8348]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:23:33 hn-dlp platform-python[8348]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:23:34 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8348]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:23:34 hn-dlp ipa-ods-exporter[8348]: Traceback (most recent call last): Jan 10 09:23:34 hn-dlp ipa-ods-exporter[8348]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:23:34 hn-dlp ipa-ods-exporter[8348]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:23:34 hn-dlp ipa-ods-exporter[8348]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:23:34 hn-dlp ipa-ods-exporter[8348]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:23:34 hn-dlp ipa-ods-exporter[8348]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:23:34 hn-dlp ipa-ods-exporter[8348]: h = self.p11.import_public_key(**params) Jan 10 09:23:34 hn-dlp ipa-ods-exporter[8348]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:23:34 hn-dlp ipa-ods-exporter[8348]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:23:34 hn-dlp ipa-ods-exporter[8348]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:23:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:23:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:23:48 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:24:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:24:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 31. Jan 10 09:24:34 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:24:34 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:24:37 hn-dlp platform-python[8358]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:24:37 hn-dlp platform-python[8358]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:24:37 hn-dlp platform-python[8358]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:24:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8358]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:24:37 hn-dlp ipa-ods-exporter[8358]: Traceback (most recent call last): Jan 10 09:24:37 hn-dlp ipa-ods-exporter[8358]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:24:37 hn-dlp ipa-ods-exporter[8358]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:24:37 hn-dlp ipa-ods-exporter[8358]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:24:37 hn-dlp ipa-ods-exporter[8358]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:24:37 hn-dlp ipa-ods-exporter[8358]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:24:37 hn-dlp ipa-ods-exporter[8358]: h = self.p11.import_public_key(**params) Jan 10 09:24:37 hn-dlp ipa-ods-exporter[8358]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:24:37 hn-dlp ipa-ods-exporter[8358]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:24:37 hn-dlp ipa-ods-exporter[8358]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:24:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:24:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:25:14 hn-dlp named-pkcs11[7597]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 09:25:14 hn-dlp named-pkcs11[7597]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:25:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:25:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 32. Jan 10 09:25:37 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:25:37 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:25:39 hn-dlp platform-python[8367]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:25:39 hn-dlp platform-python[8367]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:25:39 hn-dlp platform-python[8367]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:25:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8367]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:25:40 hn-dlp ipa-ods-exporter[8367]: Traceback (most recent call last): Jan 10 09:25:40 hn-dlp ipa-ods-exporter[8367]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:25:40 hn-dlp ipa-ods-exporter[8367]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:25:40 hn-dlp ipa-ods-exporter[8367]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:25:40 hn-dlp ipa-ods-exporter[8367]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:25:40 hn-dlp ipa-ods-exporter[8367]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:25:40 hn-dlp ipa-ods-exporter[8367]: h = self.p11.import_public_key(**params) Jan 10 09:25:40 hn-dlp ipa-ods-exporter[8367]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:25:40 hn-dlp ipa-ods-exporter[8367]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:25:40 hn-dlp ipa-ods-exporter[8367]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:25:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:25:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:25:48 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:26:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:26:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 33. Jan 10 09:26:40 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:26:40 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:26:43 hn-dlp platform-python[8376]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:26:43 hn-dlp platform-python[8376]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:26:43 hn-dlp platform-python[8376]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:26:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8376]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:26:43 hn-dlp ipa-ods-exporter[8376]: Traceback (most recent call last): Jan 10 09:26:43 hn-dlp ipa-ods-exporter[8376]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:26:43 hn-dlp ipa-ods-exporter[8376]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:26:43 hn-dlp ipa-ods-exporter[8376]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:26:43 hn-dlp ipa-ods-exporter[8376]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:26:43 hn-dlp ipa-ods-exporter[8376]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:26:43 hn-dlp ipa-ods-exporter[8376]: h = self.p11.import_public_key(**params) Jan 10 09:26:43 hn-dlp ipa-ods-exporter[8376]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:26:43 hn-dlp ipa-ods-exporter[8376]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:26:43 hn-dlp ipa-ods-exporter[8376]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:26:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:26:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:27:15 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:27:15 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:27:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:27:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 34. Jan 10 09:27:43 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:27:43 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:27:46 hn-dlp platform-python[8383]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:27:46 hn-dlp platform-python[8383]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:27:46 hn-dlp platform-python[8383]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:27:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8383]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:27:46 hn-dlp ipa-ods-exporter[8383]: Traceback (most recent call last): Jan 10 09:27:46 hn-dlp ipa-ods-exporter[8383]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:27:46 hn-dlp ipa-ods-exporter[8383]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:27:46 hn-dlp ipa-ods-exporter[8383]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:27:46 hn-dlp ipa-ods-exporter[8383]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:27:46 hn-dlp ipa-ods-exporter[8383]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:27:46 hn-dlp ipa-ods-exporter[8383]: h = self.p11.import_public_key(**params) Jan 10 09:27:46 hn-dlp ipa-ods-exporter[8383]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:27:46 hn-dlp ipa-ods-exporter[8383]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:27:46 hn-dlp ipa-ods-exporter[8383]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:27:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:27:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:27:48 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:28:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:28:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 35. Jan 10 09:28:46 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:28:46 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:28:49 hn-dlp platform-python[8394]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:28:49 hn-dlp platform-python[8394]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:28:49 hn-dlp platform-python[8394]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:28:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8394]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:28:49 hn-dlp ipa-ods-exporter[8394]: Traceback (most recent call last): Jan 10 09:28:49 hn-dlp ipa-ods-exporter[8394]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:28:49 hn-dlp ipa-ods-exporter[8394]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:28:49 hn-dlp ipa-ods-exporter[8394]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:28:49 hn-dlp ipa-ods-exporter[8394]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:28:49 hn-dlp ipa-ods-exporter[8394]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:28:49 hn-dlp ipa-ods-exporter[8394]: h = self.p11.import_public_key(**params) Jan 10 09:28:49 hn-dlp ipa-ods-exporter[8394]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:28:49 hn-dlp ipa-ods-exporter[8394]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:28:49 hn-dlp ipa-ods-exporter[8394]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:28:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:28:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:29:15 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:29:15 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:29:48 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:29:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:29:49 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 36. Jan 10 09:29:49 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:29:49 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:29:52 hn-dlp platform-python[8402]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:29:52 hn-dlp platform-python[8402]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:29:52 hn-dlp platform-python[8402]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:29:52 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8402]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:29:52 hn-dlp ipa-ods-exporter[8402]: Traceback (most recent call last): Jan 10 09:29:52 hn-dlp ipa-ods-exporter[8402]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:29:52 hn-dlp ipa-ods-exporter[8402]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:29:52 hn-dlp ipa-ods-exporter[8402]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:29:52 hn-dlp ipa-ods-exporter[8402]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:29:52 hn-dlp ipa-ods-exporter[8402]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:29:52 hn-dlp ipa-ods-exporter[8402]: h = self.p11.import_public_key(**params) Jan 10 09:29:52 hn-dlp ipa-ods-exporter[8402]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:29:52 hn-dlp ipa-ods-exporter[8402]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:29:52 hn-dlp ipa-ods-exporter[8402]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:29:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:29:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:30:31 hn-dlp systemd[1]: Created slice User Slice of UID 2002. Jan 10 09:30:31 hn-dlp systemd[1]: Started /run/user/2002 mount wrapper. Jan 10 09:30:31 hn-dlp systemd[1]: Starting User Manager for UID 2002... Jan 10 09:30:32 hn-dlp systemd-logind[744]: New session 10 of user svcforeman. Jan 10 09:30:32 hn-dlp systemd[1]: Started Session 10 of user svcforeman. Jan 10 09:30:32 hn-dlp systemd[8417]: Started Mark boot as successful after the user session has run 2 minutes. Jan 10 09:30:32 hn-dlp systemd[8417]: Reached target Timers. Jan 10 09:30:32 hn-dlp systemd[8417]: Reached target Paths. Jan 10 09:30:32 hn-dlp systemd[8417]: Starting D-Bus User Message Bus Socket. Jan 10 09:30:32 hn-dlp systemd[8417]: Listening on D-Bus User Message Bus Socket. Jan 10 09:30:32 hn-dlp systemd[8417]: Reached target Sockets. Jan 10 09:30:32 hn-dlp systemd[8417]: Reached target Basic System. Jan 10 09:30:32 hn-dlp systemd[8417]: Reached target Default. Jan 10 09:30:32 hn-dlp systemd[8417]: Startup finished in 132ms. Jan 10 09:30:32 hn-dlp systemd[1]: Started User Manager for UID 2002. Jan 10 09:30:35 hn-dlp platform-python[8580]: ansible-setup Invoked with gather_timeout=10 gather_subset=['all'] filter=* fact_path=/etc/ansible/facts.d Jan 10 09:30:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:30:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 37. Jan 10 09:30:52 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:30:52 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:30:55 hn-dlp platform-python[8686]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:30:55 hn-dlp platform-python[8686]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:30:55 hn-dlp platform-python[8686]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:30:55 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8686]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:30:55 hn-dlp ipa-ods-exporter[8686]: Traceback (most recent call last): Jan 10 09:30:55 hn-dlp ipa-ods-exporter[8686]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:30:55 hn-dlp ipa-ods-exporter[8686]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:30:55 hn-dlp ipa-ods-exporter[8686]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:30:55 hn-dlp ipa-ods-exporter[8686]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:30:55 hn-dlp ipa-ods-exporter[8686]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:30:55 hn-dlp ipa-ods-exporter[8686]: h = self.p11.import_public_key(**params) Jan 10 09:30:55 hn-dlp ipa-ods-exporter[8686]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:30:55 hn-dlp ipa-ods-exporter[8686]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:30:55 hn-dlp ipa-ods-exporter[8686]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:30:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:30:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:31:15 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:31:15 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:31:41 hn-dlp systemd[1]: session-10.scope: Succeeded. Jan 10 09:31:41 hn-dlp systemd-logind[744]: Session 10 logged out. Waiting for processes to exit. Jan 10 09:31:41 hn-dlp systemd-logind[744]: Removed session 10. Jan 10 09:31:41 hn-dlp systemd[1]: Stopping User Manager for UID 2002... Jan 10 09:31:41 hn-dlp systemd[8417]: Stopped target Default. Jan 10 09:31:41 hn-dlp systemd[8417]: Stopped target Basic System. Jan 10 09:31:41 hn-dlp systemd[8417]: Stopped target Timers. Jan 10 09:31:41 hn-dlp systemd[8417]: grub-boot-success.timer: Succeeded. Jan 10 09:31:41 hn-dlp systemd[8417]: Stopped Mark boot as successful after the user session has run 2 minutes. Jan 10 09:31:41 hn-dlp systemd[8417]: Stopped target Paths. Jan 10 09:31:41 hn-dlp systemd[8417]: Stopped target Sockets. Jan 10 09:31:41 hn-dlp systemd[8417]: dbus.socket: Succeeded. Jan 10 09:31:41 hn-dlp systemd[8417]: Closed D-Bus User Message Bus Socket. Jan 10 09:31:41 hn-dlp systemd[8417]: Reached target Shutdown. Jan 10 09:31:41 hn-dlp systemd[8417]: Starting Exit the Session... Jan 10 09:31:41 hn-dlp systemd[1]: user@2002.service: Succeeded. Jan 10 09:31:41 hn-dlp systemd[1]: Stopped User Manager for UID 2002. Jan 10 09:31:41 hn-dlp systemd[1]: Stopping /run/user/2002 mount wrapper... Jan 10 09:31:41 hn-dlp systemd[1]: Removed slice User Slice of UID 2002. Jan 10 09:31:41 hn-dlp systemd[2804]: run-user-2002.mount: Succeeded. Jan 10 09:31:41 hn-dlp systemd[1]: run-user-2002.mount: Succeeded. Jan 10 09:31:41 hn-dlp systemd[1]: user-runtime-dir@2002.service: Succeeded. Jan 10 09:31:41 hn-dlp systemd[1]: Stopped /run/user/2002 mount wrapper. Jan 10 09:31:49 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:31:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:31:55 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 38. Jan 10 09:31:55 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:31:55 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:31:58 hn-dlp platform-python[8705]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:31:58 hn-dlp platform-python[8705]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:31:58 hn-dlp platform-python[8705]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:31:58 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8705]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:31:58 hn-dlp ipa-ods-exporter[8705]: Traceback (most recent call last): Jan 10 09:31:58 hn-dlp ipa-ods-exporter[8705]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:31:58 hn-dlp ipa-ods-exporter[8705]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:31:58 hn-dlp ipa-ods-exporter[8705]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:31:58 hn-dlp ipa-ods-exporter[8705]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:31:58 hn-dlp ipa-ods-exporter[8705]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:31:58 hn-dlp ipa-ods-exporter[8705]: h = self.p11.import_public_key(**params) Jan 10 09:31:58 hn-dlp ipa-ods-exporter[8705]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:31:58 hn-dlp ipa-ods-exporter[8705]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:31:58 hn-dlp ipa-ods-exporter[8705]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:31:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:31:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:32:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:32:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 39. Jan 10 09:32:59 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:32:59 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:33:01 hn-dlp platform-python[8714]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:33:01 hn-dlp platform-python[8714]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:33:01 hn-dlp platform-python[8714]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:33:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8714]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:33:02 hn-dlp ipa-ods-exporter[8714]: Traceback (most recent call last): Jan 10 09:33:02 hn-dlp ipa-ods-exporter[8714]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:33:02 hn-dlp ipa-ods-exporter[8714]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:33:02 hn-dlp ipa-ods-exporter[8714]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:33:02 hn-dlp ipa-ods-exporter[8714]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:33:02 hn-dlp ipa-ods-exporter[8714]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:33:02 hn-dlp ipa-ods-exporter[8714]: h = self.p11.import_public_key(**params) Jan 10 09:33:02 hn-dlp ipa-ods-exporter[8714]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:33:02 hn-dlp ipa-ods-exporter[8714]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:33:02 hn-dlp ipa-ods-exporter[8714]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:33:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:33:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:33:15 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:33:15 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:33:49 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:34:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:34:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 40. Jan 10 09:34:02 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:34:02 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:34:04 hn-dlp platform-python[8724]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:34:04 hn-dlp platform-python[8724]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:34:04 hn-dlp platform-python[8724]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:34:05 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8724]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:34:05 hn-dlp ipa-ods-exporter[8724]: Traceback (most recent call last): Jan 10 09:34:05 hn-dlp ipa-ods-exporter[8724]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:34:05 hn-dlp ipa-ods-exporter[8724]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:34:05 hn-dlp ipa-ods-exporter[8724]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:34:05 hn-dlp ipa-ods-exporter[8724]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:34:05 hn-dlp ipa-ods-exporter[8724]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:34:05 hn-dlp ipa-ods-exporter[8724]: h = self.p11.import_public_key(**params) Jan 10 09:34:05 hn-dlp ipa-ods-exporter[8724]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:34:05 hn-dlp ipa-ods-exporter[8724]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:34:05 hn-dlp ipa-ods-exporter[8724]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:34:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:34:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:35:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:35:05 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 41. Jan 10 09:35:05 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:35:05 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:35:08 hn-dlp platform-python[8732]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:35:08 hn-dlp platform-python[8732]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:35:08 hn-dlp platform-python[8732]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:35:08 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8732]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:35:08 hn-dlp ipa-ods-exporter[8732]: Traceback (most recent call last): Jan 10 09:35:08 hn-dlp ipa-ods-exporter[8732]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:35:08 hn-dlp ipa-ods-exporter[8732]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:35:08 hn-dlp ipa-ods-exporter[8732]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:35:08 hn-dlp ipa-ods-exporter[8732]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:35:08 hn-dlp ipa-ods-exporter[8732]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:35:08 hn-dlp ipa-ods-exporter[8732]: h = self.p11.import_public_key(**params) Jan 10 09:35:08 hn-dlp ipa-ods-exporter[8732]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:35:08 hn-dlp ipa-ods-exporter[8732]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:35:08 hn-dlp ipa-ods-exporter[8732]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:35:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:35:08 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:35:16 hn-dlp named-pkcs11[7597]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 09:35:16 hn-dlp named-pkcs11[7597]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:35:49 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:36:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:36:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 42. Jan 10 09:36:09 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:36:09 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:36:11 hn-dlp platform-python[8742]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:36:11 hn-dlp platform-python[8742]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:36:11 hn-dlp platform-python[8742]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:36:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8742]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:36:12 hn-dlp ipa-ods-exporter[8742]: Traceback (most recent call last): Jan 10 09:36:12 hn-dlp ipa-ods-exporter[8742]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:36:12 hn-dlp ipa-ods-exporter[8742]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:36:12 hn-dlp ipa-ods-exporter[8742]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:36:12 hn-dlp ipa-ods-exporter[8742]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:36:12 hn-dlp ipa-ods-exporter[8742]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:36:12 hn-dlp ipa-ods-exporter[8742]: h = self.p11.import_public_key(**params) Jan 10 09:36:12 hn-dlp ipa-ods-exporter[8742]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:36:12 hn-dlp ipa-ods-exporter[8742]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:36:12 hn-dlp ipa-ods-exporter[8742]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:36:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:36:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:37:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:37:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 43. Jan 10 09:37:12 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:37:12 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:37:14 hn-dlp platform-python[8752]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:37:14 hn-dlp platform-python[8752]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:37:14 hn-dlp platform-python[8752]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:37:15 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8752]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:37:15 hn-dlp ipa-ods-exporter[8752]: Traceback (most recent call last): Jan 10 09:37:15 hn-dlp ipa-ods-exporter[8752]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:37:15 hn-dlp ipa-ods-exporter[8752]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:37:15 hn-dlp ipa-ods-exporter[8752]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:37:15 hn-dlp ipa-ods-exporter[8752]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:37:15 hn-dlp ipa-ods-exporter[8752]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:37:15 hn-dlp ipa-ods-exporter[8752]: h = self.p11.import_public_key(**params) Jan 10 09:37:15 hn-dlp ipa-ods-exporter[8752]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:37:15 hn-dlp ipa-ods-exporter[8752]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:37:15 hn-dlp ipa-ods-exporter[8752]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:37:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:37:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:37:16 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:37:16 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:37:49 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:38:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:38:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 44. Jan 10 09:38:15 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:38:15 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:38:16 hn-dlp rsyslogd[1019]: imjournal: journal files changed, reloading... [v8.1911.0-6.el8 try https://www.rsyslog.com/e/0 ] Jan 10 09:38:18 hn-dlp platform-python[8761]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:38:18 hn-dlp platform-python[8761]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:38:18 hn-dlp platform-python[8761]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:38:18 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8761]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:38:18 hn-dlp ipa-ods-exporter[8761]: Traceback (most recent call last): Jan 10 09:38:18 hn-dlp ipa-ods-exporter[8761]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:38:18 hn-dlp ipa-ods-exporter[8761]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:38:18 hn-dlp ipa-ods-exporter[8761]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:38:18 hn-dlp ipa-ods-exporter[8761]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:38:18 hn-dlp ipa-ods-exporter[8761]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:38:18 hn-dlp ipa-ods-exporter[8761]: h = self.p11.import_public_key(**params) Jan 10 09:38:18 hn-dlp ipa-ods-exporter[8761]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:38:18 hn-dlp ipa-ods-exporter[8761]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:38:18 hn-dlp ipa-ods-exporter[8761]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:38:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:38:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:39:17 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:39:17 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:39:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:39:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 45. Jan 10 09:39:18 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:39:18 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:39:21 hn-dlp platform-python[8772]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:39:21 hn-dlp platform-python[8772]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:39:21 hn-dlp platform-python[8772]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:39:21 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8772]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:39:21 hn-dlp ipa-ods-exporter[8772]: Traceback (most recent call last): Jan 10 09:39:21 hn-dlp ipa-ods-exporter[8772]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:39:21 hn-dlp ipa-ods-exporter[8772]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:39:21 hn-dlp ipa-ods-exporter[8772]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:39:21 hn-dlp ipa-ods-exporter[8772]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:39:21 hn-dlp ipa-ods-exporter[8772]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:39:21 hn-dlp ipa-ods-exporter[8772]: h = self.p11.import_public_key(**params) Jan 10 09:39:21 hn-dlp ipa-ods-exporter[8772]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:39:21 hn-dlp ipa-ods-exporter[8772]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:39:21 hn-dlp ipa-ods-exporter[8772]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:39:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:39:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:39:49 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:40:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:40:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 46. Jan 10 09:40:22 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:40:22 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:40:24 hn-dlp platform-python[8781]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:40:24 hn-dlp platform-python[8781]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:40:24 hn-dlp platform-python[8781]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:40:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8781]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:40:25 hn-dlp ipa-ods-exporter[8781]: Traceback (most recent call last): Jan 10 09:40:25 hn-dlp ipa-ods-exporter[8781]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:40:25 hn-dlp ipa-ods-exporter[8781]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:40:25 hn-dlp ipa-ods-exporter[8781]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:40:25 hn-dlp ipa-ods-exporter[8781]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:40:25 hn-dlp ipa-ods-exporter[8781]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:40:25 hn-dlp ipa-ods-exporter[8781]: h = self.p11.import_public_key(**params) Jan 10 09:40:25 hn-dlp ipa-ods-exporter[8781]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:40:25 hn-dlp ipa-ods-exporter[8781]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:40:25 hn-dlp ipa-ods-exporter[8781]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:40:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:40:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:41:17 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:41:17 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:41:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:41:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 47. Jan 10 09:41:25 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:41:25 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:41:28 hn-dlp platform-python[8792]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:41:28 hn-dlp platform-python[8792]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:41:28 hn-dlp platform-python[8792]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:41:28 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8792]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:41:28 hn-dlp ipa-ods-exporter[8792]: Traceback (most recent call last): Jan 10 09:41:28 hn-dlp ipa-ods-exporter[8792]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:41:28 hn-dlp ipa-ods-exporter[8792]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:41:28 hn-dlp ipa-ods-exporter[8792]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:41:28 hn-dlp ipa-ods-exporter[8792]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:41:28 hn-dlp ipa-ods-exporter[8792]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:41:28 hn-dlp ipa-ods-exporter[8792]: h = self.p11.import_public_key(**params) Jan 10 09:41:28 hn-dlp ipa-ods-exporter[8792]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:41:28 hn-dlp ipa-ods-exporter[8792]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:41:28 hn-dlp ipa-ods-exporter[8792]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:41:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:41:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:41:50 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:42:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:42:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 48. Jan 10 09:42:28 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:42:28 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:42:31 hn-dlp platform-python[8802]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:42:31 hn-dlp platform-python[8802]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:42:31 hn-dlp platform-python[8802]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:42:31 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8802]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:42:31 hn-dlp ipa-ods-exporter[8802]: Traceback (most recent call last): Jan 10 09:42:31 hn-dlp ipa-ods-exporter[8802]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:42:31 hn-dlp ipa-ods-exporter[8802]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:42:31 hn-dlp ipa-ods-exporter[8802]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:42:31 hn-dlp ipa-ods-exporter[8802]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:42:31 hn-dlp ipa-ods-exporter[8802]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:42:31 hn-dlp ipa-ods-exporter[8802]: h = self.p11.import_public_key(**params) Jan 10 09:42:31 hn-dlp ipa-ods-exporter[8802]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:42:31 hn-dlp ipa-ods-exporter[8802]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:42:31 hn-dlp ipa-ods-exporter[8802]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:42:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:42:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:43:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:43:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:43:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:43:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 49. Jan 10 09:43:31 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:43:31 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:43:34 hn-dlp platform-python[8810]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:43:34 hn-dlp platform-python[8810]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:43:34 hn-dlp platform-python[8810]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:43:34 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8810]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:43:34 hn-dlp ipa-ods-exporter[8810]: Traceback (most recent call last): Jan 10 09:43:34 hn-dlp ipa-ods-exporter[8810]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:43:34 hn-dlp ipa-ods-exporter[8810]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:43:34 hn-dlp ipa-ods-exporter[8810]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:43:34 hn-dlp ipa-ods-exporter[8810]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:43:34 hn-dlp ipa-ods-exporter[8810]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:43:34 hn-dlp ipa-ods-exporter[8810]: h = self.p11.import_public_key(**params) Jan 10 09:43:34 hn-dlp ipa-ods-exporter[8810]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:43:34 hn-dlp ipa-ods-exporter[8810]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:43:34 hn-dlp ipa-ods-exporter[8810]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:43:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:43:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:43:50 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:44:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:44:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 50. Jan 10 09:44:34 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:44:34 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:44:37 hn-dlp platform-python[8818]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:44:37 hn-dlp platform-python[8818]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:44:37 hn-dlp platform-python[8818]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:44:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8818]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:44:37 hn-dlp ipa-ods-exporter[8818]: Traceback (most recent call last): Jan 10 09:44:37 hn-dlp ipa-ods-exporter[8818]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:44:37 hn-dlp ipa-ods-exporter[8818]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:44:37 hn-dlp ipa-ods-exporter[8818]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:44:37 hn-dlp ipa-ods-exporter[8818]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:44:37 hn-dlp ipa-ods-exporter[8818]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:44:37 hn-dlp ipa-ods-exporter[8818]: h = self.p11.import_public_key(**params) Jan 10 09:44:37 hn-dlp ipa-ods-exporter[8818]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:44:37 hn-dlp ipa-ods-exporter[8818]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:44:37 hn-dlp ipa-ods-exporter[8818]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:44:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:44:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:45:18 hn-dlp named-pkcs11[7597]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 09:45:18 hn-dlp named-pkcs11[7597]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:45:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:45:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 51. Jan 10 09:45:37 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:45:37 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:45:40 hn-dlp platform-python[8828]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:45:40 hn-dlp platform-python[8828]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:45:40 hn-dlp platform-python[8828]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:45:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8828]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:45:40 hn-dlp ipa-ods-exporter[8828]: Traceback (most recent call last): Jan 10 09:45:40 hn-dlp ipa-ods-exporter[8828]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:45:40 hn-dlp ipa-ods-exporter[8828]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:45:40 hn-dlp ipa-ods-exporter[8828]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:45:40 hn-dlp ipa-ods-exporter[8828]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:45:40 hn-dlp ipa-ods-exporter[8828]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:45:40 hn-dlp ipa-ods-exporter[8828]: h = self.p11.import_public_key(**params) Jan 10 09:45:40 hn-dlp ipa-ods-exporter[8828]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:45:40 hn-dlp ipa-ods-exporter[8828]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:45:40 hn-dlp ipa-ods-exporter[8828]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:45:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:45:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:45:50 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:46:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:46:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 52. Jan 10 09:46:40 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:46:40 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:46:43 hn-dlp platform-python[8836]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:46:43 hn-dlp platform-python[8836]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:46:43 hn-dlp platform-python[8836]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:46:43 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8836]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:46:43 hn-dlp ipa-ods-exporter[8836]: Traceback (most recent call last): Jan 10 09:46:43 hn-dlp ipa-ods-exporter[8836]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:46:43 hn-dlp ipa-ods-exporter[8836]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:46:43 hn-dlp ipa-ods-exporter[8836]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:46:43 hn-dlp ipa-ods-exporter[8836]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:46:43 hn-dlp ipa-ods-exporter[8836]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:46:43 hn-dlp ipa-ods-exporter[8836]: h = self.p11.import_public_key(**params) Jan 10 09:46:43 hn-dlp ipa-ods-exporter[8836]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:46:43 hn-dlp ipa-ods-exporter[8836]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:46:43 hn-dlp ipa-ods-exporter[8836]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:46:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:46:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:47:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:47:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:47:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:47:43 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 53. Jan 10 09:47:43 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:47:43 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:47:46 hn-dlp platform-python[8846]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:47:46 hn-dlp platform-python[8846]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:47:46 hn-dlp platform-python[8846]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:47:46 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8846]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:47:46 hn-dlp ipa-ods-exporter[8846]: Traceback (most recent call last): Jan 10 09:47:46 hn-dlp ipa-ods-exporter[8846]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:47:46 hn-dlp ipa-ods-exporter[8846]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:47:46 hn-dlp ipa-ods-exporter[8846]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:47:46 hn-dlp ipa-ods-exporter[8846]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:47:46 hn-dlp ipa-ods-exporter[8846]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:47:46 hn-dlp ipa-ods-exporter[8846]: h = self.p11.import_public_key(**params) Jan 10 09:47:46 hn-dlp ipa-ods-exporter[8846]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:47:46 hn-dlp ipa-ods-exporter[8846]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:47:46 hn-dlp ipa-ods-exporter[8846]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:47:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:47:46 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:47:50 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:48:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:48:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 54. Jan 10 09:48:47 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:48:47 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:48:49 hn-dlp platform-python[8857]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:48:49 hn-dlp platform-python[8857]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:48:49 hn-dlp platform-python[8857]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:48:49 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8857]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:48:49 hn-dlp ipa-ods-exporter[8857]: Traceback (most recent call last): Jan 10 09:48:49 hn-dlp ipa-ods-exporter[8857]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:48:49 hn-dlp ipa-ods-exporter[8857]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:48:49 hn-dlp ipa-ods-exporter[8857]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:48:49 hn-dlp ipa-ods-exporter[8857]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:48:49 hn-dlp ipa-ods-exporter[8857]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:48:49 hn-dlp ipa-ods-exporter[8857]: h = self.p11.import_public_key(**params) Jan 10 09:48:49 hn-dlp ipa-ods-exporter[8857]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:48:49 hn-dlp ipa-ods-exporter[8857]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:48:49 hn-dlp ipa-ods-exporter[8857]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:48:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:48:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:49:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:49:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:49:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:49:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 55. Jan 10 09:49:50 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:49:50 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:49:50 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:49:53 hn-dlp platform-python[8866]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:49:53 hn-dlp platform-python[8866]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:49:53 hn-dlp platform-python[8866]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:49:53 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8866]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:49:53 hn-dlp ipa-ods-exporter[8866]: Traceback (most recent call last): Jan 10 09:49:53 hn-dlp ipa-ods-exporter[8866]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:49:53 hn-dlp ipa-ods-exporter[8866]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:49:53 hn-dlp ipa-ods-exporter[8866]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:49:53 hn-dlp ipa-ods-exporter[8866]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:49:53 hn-dlp ipa-ods-exporter[8866]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:49:53 hn-dlp ipa-ods-exporter[8866]: h = self.p11.import_public_key(**params) Jan 10 09:49:53 hn-dlp ipa-ods-exporter[8866]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:49:53 hn-dlp ipa-ods-exporter[8866]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:49:53 hn-dlp ipa-ods-exporter[8866]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:49:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:49:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:50:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:50:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 56. Jan 10 09:50:54 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:50:54 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:50:56 hn-dlp platform-python[8877]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:50:56 hn-dlp platform-python[8877]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:50:56 hn-dlp platform-python[8877]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:50:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8877]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:50:56 hn-dlp ipa-ods-exporter[8877]: Traceback (most recent call last): Jan 10 09:50:56 hn-dlp ipa-ods-exporter[8877]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:50:56 hn-dlp ipa-ods-exporter[8877]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:50:56 hn-dlp ipa-ods-exporter[8877]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:50:56 hn-dlp ipa-ods-exporter[8877]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:50:56 hn-dlp ipa-ods-exporter[8877]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:50:56 hn-dlp ipa-ods-exporter[8877]: h = self.p11.import_public_key(**params) Jan 10 09:50:56 hn-dlp ipa-ods-exporter[8877]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:50:56 hn-dlp ipa-ods-exporter[8877]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:50:56 hn-dlp ipa-ods-exporter[8877]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:50:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:50:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:51:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:51:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:51:51 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:51:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:51:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 57. Jan 10 09:51:57 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:51:57 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:51:59 hn-dlp platform-python[8888]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:51:59 hn-dlp platform-python[8888]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:51:59 hn-dlp platform-python[8888]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:52:00 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8888]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:52:00 hn-dlp ipa-ods-exporter[8888]: Traceback (most recent call last): Jan 10 09:52:00 hn-dlp ipa-ods-exporter[8888]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:52:00 hn-dlp ipa-ods-exporter[8888]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:52:00 hn-dlp ipa-ods-exporter[8888]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:52:00 hn-dlp ipa-ods-exporter[8888]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:52:00 hn-dlp ipa-ods-exporter[8888]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:52:00 hn-dlp ipa-ods-exporter[8888]: h = self.p11.import_public_key(**params) Jan 10 09:52:00 hn-dlp ipa-ods-exporter[8888]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:52:00 hn-dlp ipa-ods-exporter[8888]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:52:00 hn-dlp ipa-ods-exporter[8888]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:52:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:52:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:53:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:53:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 58. Jan 10 09:53:00 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:53:00 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:53:02 hn-dlp platform-python[8898]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:53:02 hn-dlp platform-python[8898]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:53:02 hn-dlp platform-python[8898]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:53:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8898]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:53:03 hn-dlp ipa-ods-exporter[8898]: Traceback (most recent call last): Jan 10 09:53:03 hn-dlp ipa-ods-exporter[8898]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:53:03 hn-dlp ipa-ods-exporter[8898]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:53:03 hn-dlp ipa-ods-exporter[8898]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:53:03 hn-dlp ipa-ods-exporter[8898]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:53:03 hn-dlp ipa-ods-exporter[8898]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:53:03 hn-dlp ipa-ods-exporter[8898]: h = self.p11.import_public_key(**params) Jan 10 09:53:03 hn-dlp ipa-ods-exporter[8898]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:53:03 hn-dlp ipa-ods-exporter[8898]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:53:03 hn-dlp ipa-ods-exporter[8898]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:53:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:53:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:53:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:53:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:53:51 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:54:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:54:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 59. Jan 10 09:54:03 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:54:03 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:54:06 hn-dlp platform-python[8906]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:54:06 hn-dlp platform-python[8906]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:54:06 hn-dlp platform-python[8906]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:54:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8906]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:54:06 hn-dlp ipa-ods-exporter[8906]: Traceback (most recent call last): Jan 10 09:54:06 hn-dlp ipa-ods-exporter[8906]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:54:06 hn-dlp ipa-ods-exporter[8906]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:54:06 hn-dlp ipa-ods-exporter[8906]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:54:06 hn-dlp ipa-ods-exporter[8906]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:54:06 hn-dlp ipa-ods-exporter[8906]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:54:06 hn-dlp ipa-ods-exporter[8906]: h = self.p11.import_public_key(**params) Jan 10 09:54:06 hn-dlp ipa-ods-exporter[8906]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:54:06 hn-dlp ipa-ods-exporter[8906]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:54:06 hn-dlp ipa-ods-exporter[8906]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:54:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:54:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:55:07 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:55:07 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 60. Jan 10 09:55:07 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:55:07 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:55:09 hn-dlp platform-python[8915]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:55:09 hn-dlp platform-python[8915]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:55:09 hn-dlp platform-python[8915]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:55:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8915]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:55:09 hn-dlp ipa-ods-exporter[8915]: Traceback (most recent call last): Jan 10 09:55:09 hn-dlp ipa-ods-exporter[8915]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:55:09 hn-dlp ipa-ods-exporter[8915]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:55:09 hn-dlp ipa-ods-exporter[8915]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:55:09 hn-dlp ipa-ods-exporter[8915]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:55:09 hn-dlp ipa-ods-exporter[8915]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:55:09 hn-dlp ipa-ods-exporter[8915]: h = self.p11.import_public_key(**params) Jan 10 09:55:09 hn-dlp ipa-ods-exporter[8915]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:55:09 hn-dlp ipa-ods-exporter[8915]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:55:09 hn-dlp ipa-ods-exporter[8915]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:55:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:55:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:55:18 hn-dlp named-pkcs11[7597]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 09:55:18 hn-dlp named-pkcs11[7597]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:55:51 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:56:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:56:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 61. Jan 10 09:56:10 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:56:10 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:56:12 hn-dlp platform-python[8924]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:56:12 hn-dlp platform-python[8924]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:56:12 hn-dlp platform-python[8924]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:56:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8924]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:56:12 hn-dlp ipa-ods-exporter[8924]: Traceback (most recent call last): Jan 10 09:56:12 hn-dlp ipa-ods-exporter[8924]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:56:12 hn-dlp ipa-ods-exporter[8924]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:56:12 hn-dlp ipa-ods-exporter[8924]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:56:12 hn-dlp ipa-ods-exporter[8924]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:56:12 hn-dlp ipa-ods-exporter[8924]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:56:12 hn-dlp ipa-ods-exporter[8924]: h = self.p11.import_public_key(**params) Jan 10 09:56:12 hn-dlp ipa-ods-exporter[8924]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:56:12 hn-dlp ipa-ods-exporter[8924]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:56:12 hn-dlp ipa-ods-exporter[8924]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:56:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:56:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:57:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:57:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 62. Jan 10 09:57:13 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:57:13 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:57:15 hn-dlp platform-python[8933]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:57:15 hn-dlp platform-python[8933]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:57:15 hn-dlp platform-python[8933]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:57:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8933]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 09:57:16 hn-dlp ipa-ods-exporter[8933]: Traceback (most recent call last): Jan 10 09:57:16 hn-dlp ipa-ods-exporter[8933]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:57:16 hn-dlp ipa-ods-exporter[8933]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:57:16 hn-dlp ipa-ods-exporter[8933]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:57:16 hn-dlp ipa-ods-exporter[8933]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:57:16 hn-dlp ipa-ods-exporter[8933]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:57:16 hn-dlp ipa-ods-exporter[8933]: h = self.p11.import_public_key(**params) Jan 10 09:57:16 hn-dlp ipa-ods-exporter[8933]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:57:16 hn-dlp ipa-ods-exporter[8933]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:57:16 hn-dlp ipa-ods-exporter[8933]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:57:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:57:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:57:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:57:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:57:51 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 09:58:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:58:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 63. Jan 10 09:58:16 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:58:16 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:58:18 hn-dlp platform-python[8943]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:58:18 hn-dlp platform-python[8943]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:58:18 hn-dlp platform-python[8943]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:58:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8943]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:58:19 hn-dlp ipa-ods-exporter[8943]: Traceback (most recent call last): Jan 10 09:58:19 hn-dlp ipa-ods-exporter[8943]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:58:19 hn-dlp ipa-ods-exporter[8943]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:58:19 hn-dlp ipa-ods-exporter[8943]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:58:19 hn-dlp ipa-ods-exporter[8943]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:58:19 hn-dlp ipa-ods-exporter[8943]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:58:19 hn-dlp ipa-ods-exporter[8943]: h = self.p11.import_public_key(**params) Jan 10 09:58:19 hn-dlp ipa-ods-exporter[8943]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:58:19 hn-dlp ipa-ods-exporter[8943]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:58:19 hn-dlp ipa-ods-exporter[8943]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:58:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:58:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:59:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 09:59:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 09:59:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 09:59:19 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 64. Jan 10 09:59:19 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 09:59:19 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 09:59:21 hn-dlp platform-python[8951]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 09:59:21 hn-dlp platform-python[8951]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 09:59:21 hn-dlp platform-python[8951]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 09:59:22 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8951]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 09:59:22 hn-dlp ipa-ods-exporter[8951]: Traceback (most recent call last): Jan 10 09:59:22 hn-dlp ipa-ods-exporter[8951]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 09:59:22 hn-dlp ipa-ods-exporter[8951]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 09:59:22 hn-dlp ipa-ods-exporter[8951]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 09:59:22 hn-dlp ipa-ods-exporter[8951]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 09:59:22 hn-dlp ipa-ods-exporter[8951]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 09:59:22 hn-dlp ipa-ods-exporter[8951]: h = self.p11.import_public_key(**params) Jan 10 09:59:22 hn-dlp ipa-ods-exporter[8951]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 09:59:22 hn-dlp ipa-ods-exporter[8951]: raise DuplicationError("Public key with same ID already exists") Jan 10 09:59:22 hn-dlp ipa-ods-exporter[8951]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 09:59:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 09:59:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 09:59:51 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:00:00 hn-dlp named-pkcs11[7597]: no valid RRSIG resolving '168.192.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 10:00:00 hn-dlp named-pkcs11[7597]: no valid DS resolving '2.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:00 hn-dlp named-pkcs11[7597]: validating 4.133.168.192.in-addr.arpa/PTR: bad cache hit (168.192.in-addr.arpa/DS) Jan 10 10:00:00 hn-dlp named-pkcs11[7597]: broken trust chain resolving '4.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:00 hn-dlp named-pkcs11[7597]: validating 3.133.168.192.in-addr.arpa/PTR: bad cache hit (168.192.in-addr.arpa/DS) Jan 10 10:00:00 hn-dlp named-pkcs11[7597]: broken trust chain resolving '3.133.168.192.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:02 hn-dlp named-pkcs11[7597]: validating 104.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:02 hn-dlp named-pkcs11[7597]: broken trust chain resolving '104.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:02 hn-dlp named-pkcs11[7597]: validating 109.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:02 hn-dlp named-pkcs11[7597]: broken trust chain resolving '109.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 110.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '110.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 113.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '113.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 191.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '191.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 192.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '192.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 203.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '203.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 254.194.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '254.194.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 104.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '104.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 171.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '171.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 173.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '173.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 183.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '183.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 204.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '204.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 213.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '213.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 216.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '216.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 217.196.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '217.196.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 1.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 5.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '5.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 14.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '14.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 15.188.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '15.188.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 1.171.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.171.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 2.171.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '2.171.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 100.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '100.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 103.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '103.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 254.174.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '254.174.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 104.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '104.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 107.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '107.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: validating 254.175.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:03 hn-dlp named-pkcs11[7597]: broken trust chain resolving '254.175.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:04 hn-dlp named-pkcs11[7597]: validating 5.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:04 hn-dlp named-pkcs11[7597]: broken trust chain resolving '5.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:04 hn-dlp named-pkcs11[7597]: validating 11.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:04 hn-dlp named-pkcs11[7597]: broken trust chain resolving '11.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:04 hn-dlp named-pkcs11[7597]: validating 100.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:04 hn-dlp named-pkcs11[7597]: broken trust chain resolving '100.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:04 hn-dlp named-pkcs11[7597]: validating 254.176.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:00:04 hn-dlp named-pkcs11[7597]: broken trust chain resolving '254.176.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:00:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:00:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 65. Jan 10 10:00:22 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:00:22 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:00:24 hn-dlp platform-python[8959]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:00:24 hn-dlp platform-python[8959]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:00:24 hn-dlp platform-python[8959]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:00:25 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[8959]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:00:25 hn-dlp ipa-ods-exporter[8959]: Traceback (most recent call last): Jan 10 10:00:25 hn-dlp ipa-ods-exporter[8959]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:00:25 hn-dlp ipa-ods-exporter[8959]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:00:25 hn-dlp ipa-ods-exporter[8959]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:00:25 hn-dlp ipa-ods-exporter[8959]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:00:25 hn-dlp ipa-ods-exporter[8959]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:00:25 hn-dlp ipa-ods-exporter[8959]: h = self.p11.import_public_key(**params) Jan 10 10:00:25 hn-dlp ipa-ods-exporter[8959]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:00:25 hn-dlp ipa-ods-exporter[8959]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:00:25 hn-dlp ipa-ods-exporter[8959]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:00:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:00:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:00:33 hn-dlp systemd[1]: Created slice User Slice of UID 2002. Jan 10 10:00:33 hn-dlp systemd[1]: Started /run/user/2002 mount wrapper. Jan 10 10:00:33 hn-dlp systemd[1]: Starting User Manager for UID 2002... Jan 10 10:00:33 hn-dlp systemd-logind[744]: New session 12 of user svcforeman. Jan 10 10:00:33 hn-dlp systemd[1]: Started Session 12 of user svcforeman. Jan 10 10:00:33 hn-dlp systemd[8973]: Started Mark boot as successful after the user session has run 2 minutes. Jan 10 10:00:33 hn-dlp systemd[8973]: Starting D-Bus User Message Bus Socket. Jan 10 10:00:33 hn-dlp systemd[8973]: Reached target Timers. Jan 10 10:00:33 hn-dlp systemd[8973]: Reached target Paths. Jan 10 10:00:33 hn-dlp systemd[8973]: Listening on D-Bus User Message Bus Socket. Jan 10 10:00:33 hn-dlp systemd[8973]: Reached target Sockets. Jan 10 10:00:33 hn-dlp systemd[8973]: Reached target Basic System. Jan 10 10:00:33 hn-dlp systemd[8973]: Reached target Default. Jan 10 10:00:33 hn-dlp systemd[8973]: Startup finished in 111ms. Jan 10 10:00:33 hn-dlp systemd[1]: Started User Manager for UID 2002. Jan 10 10:00:36 hn-dlp platform-python[9136]: ansible-setup Invoked with gather_timeout=10 gather_subset=['all'] filter=* fact_path=/etc/ansible/facts.d Jan 10 10:01:05 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.48' (uid=0 pid=677 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 10:01:05 hn-dlp dbus-daemon[9253]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 10:01:06 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 10:01:07 hn-dlp setroubleshoot[9253]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der Jan 10 10:01:07 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.408' (uid=995 pid=9253 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 10:01:07 hn-dlp dbus-daemon[9265]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 10:01:08 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 10:01:12 hn-dlp setroubleshoot[9253]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 10:01:12 hn-dlp setroubleshoot[9253]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-090000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 10:01:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:01:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:01:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:01:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 66. Jan 10 10:01:25 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:01:25 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:01:32 hn-dlp platform-python[9270]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:01:32 hn-dlp platform-python[9270]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:01:32 hn-dlp platform-python[9270]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:01:32 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9270]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:01:32 hn-dlp ipa-ods-exporter[9270]: Traceback (most recent call last): Jan 10 10:01:32 hn-dlp ipa-ods-exporter[9270]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:01:32 hn-dlp ipa-ods-exporter[9270]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:01:32 hn-dlp ipa-ods-exporter[9270]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:01:32 hn-dlp ipa-ods-exporter[9270]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:01:32 hn-dlp ipa-ods-exporter[9270]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:01:32 hn-dlp ipa-ods-exporter[9270]: h = self.p11.import_public_key(**params) Jan 10 10:01:32 hn-dlp ipa-ods-exporter[9270]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:01:32 hn-dlp ipa-ods-exporter[9270]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:01:32 hn-dlp ipa-ods-exporter[9270]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:01:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:01:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:01:32 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.48' (uid=0 pid=677 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 10:01:32 hn-dlp dbus-daemon[9280]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 10:01:34 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 10:01:35 hn-dlp setroubleshoot[9280]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der Jan 10 10:01:35 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.414' (uid=995 pid=9280 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 10:01:35 hn-dlp dbus-daemon[9293]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 10:01:36 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 10:01:38 hn-dlp setroubleshoot[9280]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 10:01:38 hn-dlp setroubleshoot[9280]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-090000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 10:01:39 hn-dlp systemd[1]: session-12.scope: Succeeded. Jan 10 10:01:39 hn-dlp systemd-logind[744]: Session 12 logged out. Waiting for processes to exit. Jan 10 10:01:39 hn-dlp systemd-logind[744]: Removed session 12. Jan 10 10:01:39 hn-dlp systemd[1]: Stopping User Manager for UID 2002... Jan 10 10:01:39 hn-dlp systemd[8973]: Stopped target Default. Jan 10 10:01:39 hn-dlp systemd[8973]: Stopped target Basic System. Jan 10 10:01:39 hn-dlp systemd[8973]: Stopped target Paths. Jan 10 10:01:39 hn-dlp systemd[8973]: Stopped target Sockets. Jan 10 10:01:39 hn-dlp systemd[8973]: dbus.socket: Succeeded. Jan 10 10:01:39 hn-dlp systemd[8973]: Closed D-Bus User Message Bus Socket. Jan 10 10:01:39 hn-dlp systemd[8973]: Stopped target Timers. Jan 10 10:01:39 hn-dlp systemd[8973]: grub-boot-success.timer: Succeeded. Jan 10 10:01:39 hn-dlp systemd[8973]: Stopped Mark boot as successful after the user session has run 2 minutes. Jan 10 10:01:39 hn-dlp systemd[8973]: Reached target Shutdown. Jan 10 10:01:39 hn-dlp systemd[8973]: Starting Exit the Session... Jan 10 10:01:39 hn-dlp systemd[1]: user@2002.service: Succeeded. Jan 10 10:01:39 hn-dlp systemd[1]: Stopped User Manager for UID 2002. Jan 10 10:01:39 hn-dlp systemd[1]: Stopping /run/user/2002 mount wrapper... Jan 10 10:01:39 hn-dlp systemd[1]: Removed slice User Slice of UID 2002. Jan 10 10:01:39 hn-dlp systemd[2804]: run-user-2002.mount: Succeeded. Jan 10 10:01:39 hn-dlp systemd[1]: run-user-2002.mount: Succeeded. Jan 10 10:01:39 hn-dlp systemd[1]: user-runtime-dir@2002.service: Succeeded. Jan 10 10:01:39 hn-dlp systemd[1]: Stopped /run/user/2002 mount wrapper. Jan 10 10:01:52 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:02:05 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.48' (uid=0 pid=677 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 10:02:05 hn-dlp dbus-daemon[9309]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 10:02:06 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 10:02:06 hn-dlp setroubleshoot[9309]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der Jan 10 10:02:06 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.420' (uid=995 pid=9309 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 10:02:06 hn-dlp dbus-daemon[9322]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 10:02:07 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 10:02:08 hn-dlp setroubleshoot[9309]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 10:02:08 hn-dlp setroubleshoot[9309]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-090000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 10:02:33 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:02:33 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 67. Jan 10 10:02:33 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:02:33 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:02:36 hn-dlp platform-python[9327]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:02:36 hn-dlp platform-python[9327]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:02:36 hn-dlp platform-python[9327]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:02:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9327]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:02:37 hn-dlp ipa-ods-exporter[9327]: Traceback (most recent call last): Jan 10 10:02:37 hn-dlp ipa-ods-exporter[9327]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:02:37 hn-dlp ipa-ods-exporter[9327]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:02:37 hn-dlp ipa-ods-exporter[9327]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:02:37 hn-dlp ipa-ods-exporter[9327]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:02:37 hn-dlp ipa-ods-exporter[9327]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:02:37 hn-dlp ipa-ods-exporter[9327]: h = self.p11.import_public_key(**params) Jan 10 10:02:37 hn-dlp ipa-ods-exporter[9327]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:02:37 hn-dlp ipa-ods-exporter[9327]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:02:37 hn-dlp ipa-ods-exporter[9327]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:02:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:02:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:03:14 hn-dlp systemd[1]: Starting dnf makecache... Jan 10 10:03:17 hn-dlp dnf[9335]: Updating Subscription Management repositories. Jan 10 10:03:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:03:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:03:20 hn-dlp dnf[9335]: CentOS Linux 8 - AppStream 8.7 kB/s | 4.3 kB 00:00 Jan 10 10:03:20 hn-dlp dnf[9335]: CentOS Linux 8 - BaseOS 11 kB/s | 3.9 kB 00:00 Jan 10 10:03:21 hn-dlp dnf[9335]: CentOS Linux 8 - Extras 14 kB/s | 1.5 kB 00:00 Jan 10 10:03:21 hn-dlp dnf[9335]: Tecin Centos 8 puppetCrlUpdater 16 kB/s | 3.4 kB 00:00 Jan 10 10:03:21 hn-dlp dnf[9335]: Rspamd8 14 kB/s | 3.5 kB 00:00 Jan 10 10:03:21 hn-dlp dnf[9335]: Puppet8 16 kB/s | 3.5 kB 00:00 Jan 10 10:03:22 hn-dlp dnf[9335]: CentOS 8 BaseOS 17 kB/s | 3.8 kB 00:00 Jan 10 10:03:22 hn-dlp dnf[9335]: Client8 17 kB/s | 3.7 kB 00:00 Jan 10 10:03:22 hn-dlp dnf[9335]: Tecin Centos 8 puppetMasterCrlUpdater 16 kB/s | 3.4 kB 00:00 Jan 10 10:03:23 hn-dlp dnf[9335]: CentOS 8 Extras 19 kB/s | 3.5 kB 00:00 Jan 10 10:03:23 hn-dlp dnf[9335]: CentOS 8 AppStream 21 kB/s | 4.1 kB 00:00 Jan 10 10:03:23 hn-dlp dnf[9335]: EPEL8 19 kB/s | 4.3 kB 00:00 Jan 10 10:03:24 hn-dlp dnf[9335]: Client8 17 kB/s | 3.5 kB 00:00 Jan 10 10:03:24 hn-dlp dnf[9335]: CentOS 8 PowerTools 17 kB/s | 4.1 kB 00:00 Jan 10 10:03:24 hn-dlp dnf[9335]: CentOS 8 CentOSPlus 16 kB/s | 3.5 kB 00:00 Jan 10 10:03:24 hn-dlp dnf[9335]: Client8-non-supported 15 kB/s | 3.4 kB 00:00 Jan 10 10:03:25 hn-dlp dnf[9335]: Tecin Centos 8 certmongerPuppetSelinuxPolicy 16 kB/s | 3.4 kB 00:00 Jan 10 10:03:26 hn-dlp dnf[9335]: Metadata cache created. Jan 10 10:03:26 hn-dlp systemd[1]: dnf-makecache.service: Succeeded. Jan 10 10:03:26 hn-dlp systemd[1]: Started dnf makecache. Jan 10 10:03:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:03:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 68. Jan 10 10:03:37 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:03:37 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:03:40 hn-dlp platform-python[9362]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:03:40 hn-dlp platform-python[9362]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:03:40 hn-dlp platform-python[9362]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:03:41 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9362]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:03:41 hn-dlp ipa-ods-exporter[9362]: Traceback (most recent call last): Jan 10 10:03:41 hn-dlp ipa-ods-exporter[9362]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:03:41 hn-dlp ipa-ods-exporter[9362]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:03:41 hn-dlp ipa-ods-exporter[9362]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:03:41 hn-dlp ipa-ods-exporter[9362]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:03:41 hn-dlp ipa-ods-exporter[9362]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:03:41 hn-dlp ipa-ods-exporter[9362]: h = self.p11.import_public_key(**params) Jan 10 10:03:41 hn-dlp ipa-ods-exporter[9362]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:03:41 hn-dlp ipa-ods-exporter[9362]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:03:41 hn-dlp ipa-ods-exporter[9362]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:03:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:03:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:03:41 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.48' (uid=0 pid=677 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 10:03:41 hn-dlp dbus-daemon[9370]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 10:03:42 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 10:03:42 hn-dlp setroubleshoot[9370]: failed to retrieve rpm info for /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der Jan 10 10:03:42 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.428' (uid=995 pid=9370 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 10:03:42 hn-dlp dbus-daemon[9383]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 10:03:43 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 10:03:44 hn-dlp setroubleshoot[9370]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der. For complete SELinux messages run: sealert -l b8aee4fd-1a30-4462-8442-cc8330d9a698 Jan 10 10:03:44 hn-dlp setroubleshoot[9370]: SELinux is preventing httpd from map access on the file /var/lib/ipa/pki-ca/publish/MasterCRL-20210110-090000.der.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow domain to can mmap files#012Then you must tell SELinux about this by enabling the 'domain_can_mmap_files' boolean.#012#012Do#012setsebool -P domain_can_mmap_files 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that httpd should be allowed map access on the MasterCRL-20210110-090000.der file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'httpd' --raw | audit2allow -M my-httpd#012# semodule -X 300 -i my-httpd.pp#012 Jan 10 10:03:52 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:04:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:04:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 69. Jan 10 10:04:41 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:04:41 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:04:44 hn-dlp platform-python[9388]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:04:44 hn-dlp platform-python[9388]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:04:44 hn-dlp platform-python[9388]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:04:44 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9388]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:04:44 hn-dlp ipa-ods-exporter[9388]: Traceback (most recent call last): Jan 10 10:04:44 hn-dlp ipa-ods-exporter[9388]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:04:44 hn-dlp ipa-ods-exporter[9388]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:04:44 hn-dlp ipa-ods-exporter[9388]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:04:44 hn-dlp ipa-ods-exporter[9388]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:04:44 hn-dlp ipa-ods-exporter[9388]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:04:44 hn-dlp ipa-ods-exporter[9388]: h = self.p11.import_public_key(**params) Jan 10 10:04:44 hn-dlp ipa-ods-exporter[9388]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:04:44 hn-dlp ipa-ods-exporter[9388]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:04:44 hn-dlp ipa-ods-exporter[9388]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:04:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:04:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:05:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:05:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:05:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:05:45 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 70. Jan 10 10:05:45 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:05:45 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:05:47 hn-dlp platform-python[9398]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:05:47 hn-dlp platform-python[9398]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:05:47 hn-dlp platform-python[9398]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:05:47 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9398]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:05:47 hn-dlp ipa-ods-exporter[9398]: Traceback (most recent call last): Jan 10 10:05:47 hn-dlp ipa-ods-exporter[9398]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:05:47 hn-dlp ipa-ods-exporter[9398]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:05:47 hn-dlp ipa-ods-exporter[9398]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:05:47 hn-dlp ipa-ods-exporter[9398]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:05:47 hn-dlp ipa-ods-exporter[9398]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:05:47 hn-dlp ipa-ods-exporter[9398]: h = self.p11.import_public_key(**params) Jan 10 10:05:47 hn-dlp ipa-ods-exporter[9398]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:05:47 hn-dlp ipa-ods-exporter[9398]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:05:47 hn-dlp ipa-ods-exporter[9398]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:05:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:05:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:05:55 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:06:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:06:48 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 71. Jan 10 10:06:48 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:06:48 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:06:50 hn-dlp platform-python[9407]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:06:50 hn-dlp platform-python[9407]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:06:50 hn-dlp platform-python[9407]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:06:51 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9407]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:06:51 hn-dlp ipa-ods-exporter[9407]: Traceback (most recent call last): Jan 10 10:06:51 hn-dlp ipa-ods-exporter[9407]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:06:51 hn-dlp ipa-ods-exporter[9407]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:06:51 hn-dlp ipa-ods-exporter[9407]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:06:51 hn-dlp ipa-ods-exporter[9407]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:06:51 hn-dlp ipa-ods-exporter[9407]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:06:51 hn-dlp ipa-ods-exporter[9407]: h = self.p11.import_public_key(**params) Jan 10 10:06:51 hn-dlp ipa-ods-exporter[9407]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:06:51 hn-dlp ipa-ods-exporter[9407]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:06:51 hn-dlp ipa-ods-exporter[9407]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:06:51 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:06:51 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:07:18 hn-dlp named-pkcs11[7597]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 10:07:18 hn-dlp named-pkcs11[7597]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:07:51 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:07:51 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 72. Jan 10 10:07:51 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:07:51 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:07:53 hn-dlp platform-python[9415]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:07:53 hn-dlp platform-python[9415]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:07:53 hn-dlp platform-python[9415]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:07:54 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9415]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:07:54 hn-dlp ipa-ods-exporter[9415]: Traceback (most recent call last): Jan 10 10:07:54 hn-dlp ipa-ods-exporter[9415]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:07:54 hn-dlp ipa-ods-exporter[9415]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:07:54 hn-dlp ipa-ods-exporter[9415]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:07:54 hn-dlp ipa-ods-exporter[9415]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:07:54 hn-dlp ipa-ods-exporter[9415]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:07:54 hn-dlp ipa-ods-exporter[9415]: h = self.p11.import_public_key(**params) Jan 10 10:07:54 hn-dlp ipa-ods-exporter[9415]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:07:54 hn-dlp ipa-ods-exporter[9415]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:07:54 hn-dlp ipa-ods-exporter[9415]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:07:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:07:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:07:55 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:08:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:08:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 73. Jan 10 10:08:54 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:08:54 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:08:57 hn-dlp platform-python[9424]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:08:57 hn-dlp platform-python[9424]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:08:57 hn-dlp platform-python[9424]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:08:57 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9424]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:08:57 hn-dlp ipa-ods-exporter[9424]: Traceback (most recent call last): Jan 10 10:08:57 hn-dlp ipa-ods-exporter[9424]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:08:57 hn-dlp ipa-ods-exporter[9424]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:08:57 hn-dlp ipa-ods-exporter[9424]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:08:57 hn-dlp ipa-ods-exporter[9424]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:08:57 hn-dlp ipa-ods-exporter[9424]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:08:57 hn-dlp ipa-ods-exporter[9424]: h = self.p11.import_public_key(**params) Jan 10 10:08:57 hn-dlp ipa-ods-exporter[9424]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:08:57 hn-dlp ipa-ods-exporter[9424]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:08:57 hn-dlp ipa-ods-exporter[9424]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:08:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:08:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:09:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:09:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:09:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:09:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:09:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 74. Jan 10 10:09:57 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:09:57 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:10:00 hn-dlp platform-python[9435]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:10:00 hn-dlp platform-python[9435]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:10:00 hn-dlp platform-python[9435]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:10:00 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9435]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:10:00 hn-dlp ipa-ods-exporter[9435]: Traceback (most recent call last): Jan 10 10:10:00 hn-dlp ipa-ods-exporter[9435]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:10:00 hn-dlp ipa-ods-exporter[9435]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:10:00 hn-dlp ipa-ods-exporter[9435]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:10:00 hn-dlp ipa-ods-exporter[9435]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:10:00 hn-dlp ipa-ods-exporter[9435]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:10:00 hn-dlp ipa-ods-exporter[9435]: h = self.p11.import_public_key(**params) Jan 10 10:10:00 hn-dlp ipa-ods-exporter[9435]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:10:00 hn-dlp ipa-ods-exporter[9435]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:10:00 hn-dlp ipa-ods-exporter[9435]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:10:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:10:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:11:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:11:01 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 75. Jan 10 10:11:01 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:11:01 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:11:03 hn-dlp platform-python[9443]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:11:03 hn-dlp platform-python[9443]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:11:03 hn-dlp platform-python[9443]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:11:03 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9443]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:11:03 hn-dlp ipa-ods-exporter[9443]: Traceback (most recent call last): Jan 10 10:11:03 hn-dlp ipa-ods-exporter[9443]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:11:03 hn-dlp ipa-ods-exporter[9443]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:11:03 hn-dlp ipa-ods-exporter[9443]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:11:03 hn-dlp ipa-ods-exporter[9443]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:11:03 hn-dlp ipa-ods-exporter[9443]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:11:03 hn-dlp ipa-ods-exporter[9443]: h = self.p11.import_public_key(**params) Jan 10 10:11:03 hn-dlp ipa-ods-exporter[9443]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:11:03 hn-dlp ipa-ods-exporter[9443]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:11:03 hn-dlp ipa-ods-exporter[9443]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:11:04 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:11:04 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:11:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:11:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:11:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:12:04 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:12:04 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 76. Jan 10 10:12:04 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:12:04 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:12:06 hn-dlp platform-python[9454]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:12:06 hn-dlp platform-python[9454]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:12:06 hn-dlp platform-python[9454]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:12:07 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9454]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:12:07 hn-dlp ipa-ods-exporter[9454]: Traceback (most recent call last): Jan 10 10:12:07 hn-dlp ipa-ods-exporter[9454]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:12:07 hn-dlp ipa-ods-exporter[9454]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:12:07 hn-dlp ipa-ods-exporter[9454]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:12:07 hn-dlp ipa-ods-exporter[9454]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:12:07 hn-dlp ipa-ods-exporter[9454]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:12:07 hn-dlp ipa-ods-exporter[9454]: h = self.p11.import_public_key(**params) Jan 10 10:12:07 hn-dlp ipa-ods-exporter[9454]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:12:07 hn-dlp ipa-ods-exporter[9454]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:12:07 hn-dlp ipa-ods-exporter[9454]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:12:07 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:12:07 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:13:07 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:13:07 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 77. Jan 10 10:13:07 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:13:07 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:13:09 hn-dlp platform-python[9464]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:13:09 hn-dlp platform-python[9464]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:13:09 hn-dlp platform-python[9464]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:13:10 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9464]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:13:10 hn-dlp ipa-ods-exporter[9464]: Traceback (most recent call last): Jan 10 10:13:10 hn-dlp ipa-ods-exporter[9464]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:13:10 hn-dlp ipa-ods-exporter[9464]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:13:10 hn-dlp ipa-ods-exporter[9464]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:13:10 hn-dlp ipa-ods-exporter[9464]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:13:10 hn-dlp ipa-ods-exporter[9464]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:13:10 hn-dlp ipa-ods-exporter[9464]: h = self.p11.import_public_key(**params) Jan 10 10:13:10 hn-dlp ipa-ods-exporter[9464]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:13:10 hn-dlp ipa-ods-exporter[9464]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:13:10 hn-dlp ipa-ods-exporter[9464]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:13:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:13:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:13:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:13:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:13:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:14:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:14:10 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 78. Jan 10 10:14:10 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:14:10 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:14:13 hn-dlp platform-python[9473]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:14:13 hn-dlp platform-python[9473]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:14:13 hn-dlp platform-python[9473]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:14:13 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9473]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:14:13 hn-dlp ipa-ods-exporter[9473]: Traceback (most recent call last): Jan 10 10:14:13 hn-dlp ipa-ods-exporter[9473]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:14:13 hn-dlp ipa-ods-exporter[9473]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:14:13 hn-dlp ipa-ods-exporter[9473]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:14:13 hn-dlp ipa-ods-exporter[9473]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:14:13 hn-dlp ipa-ods-exporter[9473]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:14:13 hn-dlp ipa-ods-exporter[9473]: h = self.p11.import_public_key(**params) Jan 10 10:14:13 hn-dlp ipa-ods-exporter[9473]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:14:13 hn-dlp ipa-ods-exporter[9473]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:14:13 hn-dlp ipa-ods-exporter[9473]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:14:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:14:13 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:15:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:15:14 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 79. Jan 10 10:15:14 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:15:14 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:15:16 hn-dlp platform-python[9483]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:15:16 hn-dlp platform-python[9483]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:15:16 hn-dlp platform-python[9483]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:15:16 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9483]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:15:16 hn-dlp ipa-ods-exporter[9483]: Traceback (most recent call last): Jan 10 10:15:16 hn-dlp ipa-ods-exporter[9483]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:15:16 hn-dlp ipa-ods-exporter[9483]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:15:16 hn-dlp ipa-ods-exporter[9483]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:15:16 hn-dlp ipa-ods-exporter[9483]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:15:16 hn-dlp ipa-ods-exporter[9483]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:15:16 hn-dlp ipa-ods-exporter[9483]: h = self.p11.import_public_key(**params) Jan 10 10:15:16 hn-dlp ipa-ods-exporter[9483]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:15:16 hn-dlp ipa-ods-exporter[9483]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:15:16 hn-dlp ipa-ods-exporter[9483]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:15:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:15:16 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:15:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:15:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:15:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:16:17 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:16:17 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 80. Jan 10 10:16:17 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:16:17 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:16:19 hn-dlp platform-python[9490]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:16:19 hn-dlp platform-python[9490]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:16:19 hn-dlp platform-python[9490]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:16:19 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9490]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:16:19 hn-dlp ipa-ods-exporter[9490]: Traceback (most recent call last): Jan 10 10:16:19 hn-dlp ipa-ods-exporter[9490]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:16:19 hn-dlp ipa-ods-exporter[9490]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:16:19 hn-dlp ipa-ods-exporter[9490]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:16:19 hn-dlp ipa-ods-exporter[9490]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:16:19 hn-dlp ipa-ods-exporter[9490]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:16:19 hn-dlp ipa-ods-exporter[9490]: h = self.p11.import_public_key(**params) Jan 10 10:16:19 hn-dlp ipa-ods-exporter[9490]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:16:19 hn-dlp ipa-ods-exporter[9490]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:16:19 hn-dlp ipa-ods-exporter[9490]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:16:20 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:16:20 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:17:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:17:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:17:20 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:17:20 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 81. Jan 10 10:17:20 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:17:20 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:17:22 hn-dlp platform-python[9499]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:17:22 hn-dlp platform-python[9499]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:17:22 hn-dlp platform-python[9499]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:17:23 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9499]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:17:23 hn-dlp ipa-ods-exporter[9499]: Traceback (most recent call last): Jan 10 10:17:23 hn-dlp ipa-ods-exporter[9499]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:17:23 hn-dlp ipa-ods-exporter[9499]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:17:23 hn-dlp ipa-ods-exporter[9499]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:17:23 hn-dlp ipa-ods-exporter[9499]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:17:23 hn-dlp ipa-ods-exporter[9499]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:17:23 hn-dlp ipa-ods-exporter[9499]: h = self.p11.import_public_key(**params) Jan 10 10:17:23 hn-dlp ipa-ods-exporter[9499]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:17:23 hn-dlp ipa-ods-exporter[9499]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:17:23 hn-dlp ipa-ods-exporter[9499]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:17:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:17:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:17:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:18:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:18:23 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 82. Jan 10 10:18:23 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:18:23 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:18:25 hn-dlp platform-python[9510]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:18:25 hn-dlp platform-python[9510]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:18:25 hn-dlp platform-python[9510]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:18:26 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9510]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:18:26 hn-dlp ipa-ods-exporter[9510]: Traceback (most recent call last): Jan 10 10:18:26 hn-dlp ipa-ods-exporter[9510]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:18:26 hn-dlp ipa-ods-exporter[9510]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:18:26 hn-dlp ipa-ods-exporter[9510]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:18:26 hn-dlp ipa-ods-exporter[9510]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:18:26 hn-dlp ipa-ods-exporter[9510]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:18:26 hn-dlp ipa-ods-exporter[9510]: h = self.p11.import_public_key(**params) Jan 10 10:18:26 hn-dlp ipa-ods-exporter[9510]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:18:26 hn-dlp ipa-ods-exporter[9510]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:18:26 hn-dlp ipa-ods-exporter[9510]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:18:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:18:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:19:18 hn-dlp named-pkcs11[7597]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 10:19:18 hn-dlp named-pkcs11[7597]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:19:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:19:26 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 83. Jan 10 10:19:26 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:19:26 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:19:28 hn-dlp platform-python[9519]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:19:28 hn-dlp platform-python[9519]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:19:28 hn-dlp platform-python[9519]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:19:29 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9519]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:19:29 hn-dlp ipa-ods-exporter[9519]: Traceback (most recent call last): Jan 10 10:19:29 hn-dlp ipa-ods-exporter[9519]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:19:29 hn-dlp ipa-ods-exporter[9519]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:19:29 hn-dlp ipa-ods-exporter[9519]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:19:29 hn-dlp ipa-ods-exporter[9519]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:19:29 hn-dlp ipa-ods-exporter[9519]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:19:29 hn-dlp ipa-ods-exporter[9519]: h = self.p11.import_public_key(**params) Jan 10 10:19:29 hn-dlp ipa-ods-exporter[9519]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:19:29 hn-dlp ipa-ods-exporter[9519]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:19:29 hn-dlp ipa-ods-exporter[9519]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:19:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:19:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:19:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:20:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:20:29 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 84. Jan 10 10:20:29 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:20:29 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:20:31 hn-dlp platform-python[9530]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:20:31 hn-dlp platform-python[9530]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:20:31 hn-dlp platform-python[9530]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:20:32 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9530]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:20:32 hn-dlp ipa-ods-exporter[9530]: Traceback (most recent call last): Jan 10 10:20:32 hn-dlp ipa-ods-exporter[9530]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:20:32 hn-dlp ipa-ods-exporter[9530]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:20:32 hn-dlp ipa-ods-exporter[9530]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:20:32 hn-dlp ipa-ods-exporter[9530]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:20:32 hn-dlp ipa-ods-exporter[9530]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:20:32 hn-dlp ipa-ods-exporter[9530]: h = self.p11.import_public_key(**params) Jan 10 10:20:32 hn-dlp ipa-ods-exporter[9530]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:20:32 hn-dlp ipa-ods-exporter[9530]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:20:32 hn-dlp ipa-ods-exporter[9530]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:20:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:20:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:21:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:21:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:21:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:21:32 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 85. Jan 10 10:21:32 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:21:32 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:21:34 hn-dlp platform-python[9540]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:21:34 hn-dlp platform-python[9540]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:21:34 hn-dlp platform-python[9540]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:21:35 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9540]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:21:35 hn-dlp ipa-ods-exporter[9540]: Traceback (most recent call last): Jan 10 10:21:35 hn-dlp ipa-ods-exporter[9540]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:21:35 hn-dlp ipa-ods-exporter[9540]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:21:35 hn-dlp ipa-ods-exporter[9540]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:21:35 hn-dlp ipa-ods-exporter[9540]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:21:35 hn-dlp ipa-ods-exporter[9540]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:21:35 hn-dlp ipa-ods-exporter[9540]: h = self.p11.import_public_key(**params) Jan 10 10:21:35 hn-dlp ipa-ods-exporter[9540]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:21:35 hn-dlp ipa-ods-exporter[9540]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:21:35 hn-dlp ipa-ods-exporter[9540]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:21:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:21:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:21:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:22:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:22:35 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 86. Jan 10 10:22:35 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:22:35 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:22:37 hn-dlp platform-python[9549]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:22:37 hn-dlp platform-python[9549]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:22:37 hn-dlp platform-python[9549]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:22:38 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9549]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:22:38 hn-dlp ipa-ods-exporter[9549]: Traceback (most recent call last): Jan 10 10:22:38 hn-dlp ipa-ods-exporter[9549]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:22:38 hn-dlp ipa-ods-exporter[9549]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:22:38 hn-dlp ipa-ods-exporter[9549]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:22:38 hn-dlp ipa-ods-exporter[9549]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:22:38 hn-dlp ipa-ods-exporter[9549]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:22:38 hn-dlp ipa-ods-exporter[9549]: h = self.p11.import_public_key(**params) Jan 10 10:22:38 hn-dlp ipa-ods-exporter[9549]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:22:38 hn-dlp ipa-ods-exporter[9549]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:22:38 hn-dlp ipa-ods-exporter[9549]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:22:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:22:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:23:18 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:23:18 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:23:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:23:38 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 87. Jan 10 10:23:38 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:23:38 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:23:40 hn-dlp platform-python[9559]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:23:40 hn-dlp platform-python[9559]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:23:40 hn-dlp platform-python[9559]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:23:41 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9559]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:23:41 hn-dlp ipa-ods-exporter[9559]: Traceback (most recent call last): Jan 10 10:23:41 hn-dlp ipa-ods-exporter[9559]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:23:41 hn-dlp ipa-ods-exporter[9559]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:23:41 hn-dlp ipa-ods-exporter[9559]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:23:41 hn-dlp ipa-ods-exporter[9559]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:23:41 hn-dlp ipa-ods-exporter[9559]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:23:41 hn-dlp ipa-ods-exporter[9559]: h = self.p11.import_public_key(**params) Jan 10 10:23:41 hn-dlp ipa-ods-exporter[9559]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:23:41 hn-dlp ipa-ods-exporter[9559]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:23:41 hn-dlp ipa-ods-exporter[9559]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:23:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:23:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:23:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:24:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:24:41 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 88. Jan 10 10:24:41 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:24:41 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:24:44 hn-dlp platform-python[9570]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:24:44 hn-dlp platform-python[9570]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:24:44 hn-dlp platform-python[9570]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:24:44 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9570]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:24:44 hn-dlp ipa-ods-exporter[9570]: Traceback (most recent call last): Jan 10 10:24:44 hn-dlp ipa-ods-exporter[9570]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:24:44 hn-dlp ipa-ods-exporter[9570]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:24:44 hn-dlp ipa-ods-exporter[9570]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:24:44 hn-dlp ipa-ods-exporter[9570]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:24:44 hn-dlp ipa-ods-exporter[9570]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:24:44 hn-dlp ipa-ods-exporter[9570]: h = self.p11.import_public_key(**params) Jan 10 10:24:44 hn-dlp ipa-ods-exporter[9570]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:24:44 hn-dlp ipa-ods-exporter[9570]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:24:44 hn-dlp ipa-ods-exporter[9570]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:24:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:24:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:25:19 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:25:19 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:25:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:25:44 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 89. Jan 10 10:25:44 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:25:44 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:25:47 hn-dlp platform-python[9579]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:25:47 hn-dlp platform-python[9579]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:25:47 hn-dlp platform-python[9579]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:25:47 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9579]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:25:47 hn-dlp ipa-ods-exporter[9579]: Traceback (most recent call last): Jan 10 10:25:47 hn-dlp ipa-ods-exporter[9579]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:25:47 hn-dlp ipa-ods-exporter[9579]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:25:47 hn-dlp ipa-ods-exporter[9579]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:25:47 hn-dlp ipa-ods-exporter[9579]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:25:47 hn-dlp ipa-ods-exporter[9579]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:25:47 hn-dlp ipa-ods-exporter[9579]: h = self.p11.import_public_key(**params) Jan 10 10:25:47 hn-dlp ipa-ods-exporter[9579]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:25:47 hn-dlp ipa-ods-exporter[9579]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:25:47 hn-dlp ipa-ods-exporter[9579]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:25:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:25:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:25:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:26:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:26:47 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 90. Jan 10 10:26:47 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:26:47 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:26:50 hn-dlp platform-python[9590]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:26:50 hn-dlp platform-python[9590]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:26:50 hn-dlp platform-python[9590]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:26:50 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9590]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:26:50 hn-dlp ipa-ods-exporter[9590]: Traceback (most recent call last): Jan 10 10:26:50 hn-dlp ipa-ods-exporter[9590]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:26:50 hn-dlp ipa-ods-exporter[9590]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:26:50 hn-dlp ipa-ods-exporter[9590]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:26:50 hn-dlp ipa-ods-exporter[9590]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:26:50 hn-dlp ipa-ods-exporter[9590]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:26:50 hn-dlp ipa-ods-exporter[9590]: h = self.p11.import_public_key(**params) Jan 10 10:26:50 hn-dlp ipa-ods-exporter[9590]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:26:50 hn-dlp ipa-ods-exporter[9590]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:26:50 hn-dlp ipa-ods-exporter[9590]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:26:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:26:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:27:19 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:27:19 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:27:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:27:50 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 91. Jan 10 10:27:50 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:27:50 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:27:53 hn-dlp platform-python[9598]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:27:53 hn-dlp platform-python[9598]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:27:53 hn-dlp platform-python[9598]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:27:53 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9598]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:27:53 hn-dlp ipa-ods-exporter[9598]: Traceback (most recent call last): Jan 10 10:27:53 hn-dlp ipa-ods-exporter[9598]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:27:53 hn-dlp ipa-ods-exporter[9598]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:27:53 hn-dlp ipa-ods-exporter[9598]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:27:53 hn-dlp ipa-ods-exporter[9598]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:27:53 hn-dlp ipa-ods-exporter[9598]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:27:53 hn-dlp ipa-ods-exporter[9598]: h = self.p11.import_public_key(**params) Jan 10 10:27:53 hn-dlp ipa-ods-exporter[9598]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:27:53 hn-dlp ipa-ods-exporter[9598]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:27:53 hn-dlp ipa-ods-exporter[9598]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:27:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:27:53 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:27:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:28:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:28:54 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 92. Jan 10 10:28:54 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:28:54 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:28:56 hn-dlp platform-python[9606]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:28:56 hn-dlp platform-python[9606]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:28:56 hn-dlp platform-python[9606]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:28:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9606]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:28:56 hn-dlp ipa-ods-exporter[9606]: Traceback (most recent call last): Jan 10 10:28:56 hn-dlp ipa-ods-exporter[9606]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:28:56 hn-dlp ipa-ods-exporter[9606]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:28:56 hn-dlp ipa-ods-exporter[9606]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:28:56 hn-dlp ipa-ods-exporter[9606]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:28:56 hn-dlp ipa-ods-exporter[9606]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:28:56 hn-dlp ipa-ods-exporter[9606]: h = self.p11.import_public_key(**params) Jan 10 10:28:56 hn-dlp ipa-ods-exporter[9606]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:28:56 hn-dlp ipa-ods-exporter[9606]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:28:56 hn-dlp ipa-ods-exporter[9606]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:28:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:28:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:29:19 hn-dlp named-pkcs11[7597]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 10:29:19 hn-dlp named-pkcs11[7597]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:29:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:29:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:29:57 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 93. Jan 10 10:29:57 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:29:57 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:29:59 hn-dlp platform-python[9616]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:29:59 hn-dlp platform-python[9616]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:29:59 hn-dlp platform-python[9616]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:29:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9616]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:29:59 hn-dlp ipa-ods-exporter[9616]: Traceback (most recent call last): Jan 10 10:29:59 hn-dlp ipa-ods-exporter[9616]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:29:59 hn-dlp ipa-ods-exporter[9616]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:29:59 hn-dlp ipa-ods-exporter[9616]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:29:59 hn-dlp ipa-ods-exporter[9616]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:29:59 hn-dlp ipa-ods-exporter[9616]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:29:59 hn-dlp ipa-ods-exporter[9616]: h = self.p11.import_public_key(**params) Jan 10 10:29:59 hn-dlp ipa-ods-exporter[9616]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:29:59 hn-dlp ipa-ods-exporter[9616]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:29:59 hn-dlp ipa-ods-exporter[9616]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:29:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:29:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:30:35 hn-dlp systemd[1]: Started /run/user/2002 mount wrapper. Jan 10 10:30:35 hn-dlp systemd[1]: Created slice User Slice of UID 2002. Jan 10 10:30:35 hn-dlp systemd[1]: Starting User Manager for UID 2002... Jan 10 10:30:35 hn-dlp systemd-logind[744]: New session 14 of user svcforeman. Jan 10 10:30:35 hn-dlp systemd[1]: Started Session 14 of user svcforeman. Jan 10 10:30:35 hn-dlp systemd[9630]: Reached target Paths. Jan 10 10:30:35 hn-dlp systemd[9630]: Started Mark boot as successful after the user session has run 2 minutes. Jan 10 10:30:35 hn-dlp systemd[9630]: Starting D-Bus User Message Bus Socket. Jan 10 10:30:35 hn-dlp systemd[9630]: Reached target Timers. Jan 10 10:30:35 hn-dlp systemd[9630]: Listening on D-Bus User Message Bus Socket. Jan 10 10:30:35 hn-dlp systemd[9630]: Reached target Sockets. Jan 10 10:30:35 hn-dlp systemd[9630]: Reached target Basic System. Jan 10 10:30:35 hn-dlp systemd[9630]: Reached target Default. Jan 10 10:30:35 hn-dlp systemd[9630]: Startup finished in 106ms. Jan 10 10:30:35 hn-dlp systemd[1]: Started User Manager for UID 2002. Jan 10 10:30:37 hn-dlp platform-python[9792]: ansible-setup Invoked with gather_timeout=10 gather_subset=['all'] filter=* fact_path=/etc/ansible/facts.d Jan 10 10:31:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:31:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 94. Jan 10 10:31:00 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:31:00 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:31:02 hn-dlp platform-python[9899]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:31:02 hn-dlp platform-python[9899]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:31:02 hn-dlp platform-python[9899]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:31:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9899]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:31:02 hn-dlp ipa-ods-exporter[9899]: Traceback (most recent call last): Jan 10 10:31:02 hn-dlp ipa-ods-exporter[9899]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:31:02 hn-dlp ipa-ods-exporter[9899]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:31:02 hn-dlp ipa-ods-exporter[9899]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:31:02 hn-dlp ipa-ods-exporter[9899]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:31:02 hn-dlp ipa-ods-exporter[9899]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:31:02 hn-dlp ipa-ods-exporter[9899]: h = self.p11.import_public_key(**params) Jan 10 10:31:02 hn-dlp ipa-ods-exporter[9899]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:31:02 hn-dlp ipa-ods-exporter[9899]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:31:02 hn-dlp ipa-ods-exporter[9899]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:31:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:31:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:31:19 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:31:19 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:31:43 hn-dlp systemd[1]: session-14.scope: Succeeded. Jan 10 10:31:43 hn-dlp systemd-logind[744]: Session 14 logged out. Waiting for processes to exit. Jan 10 10:31:43 hn-dlp systemd-logind[744]: Removed session 14. Jan 10 10:31:43 hn-dlp systemd[1]: Stopping User Manager for UID 2002... Jan 10 10:31:43 hn-dlp systemd[9630]: Stopped target Default. Jan 10 10:31:43 hn-dlp systemd[9630]: Stopped target Basic System. Jan 10 10:31:43 hn-dlp systemd[9630]: Stopped target Sockets. Jan 10 10:31:43 hn-dlp systemd[9630]: dbus.socket: Succeeded. Jan 10 10:31:43 hn-dlp systemd[9630]: Closed D-Bus User Message Bus Socket. Jan 10 10:31:43 hn-dlp systemd[9630]: Stopped target Paths. Jan 10 10:31:43 hn-dlp systemd[9630]: Stopped target Timers. Jan 10 10:31:43 hn-dlp systemd[9630]: grub-boot-success.timer: Succeeded. Jan 10 10:31:43 hn-dlp systemd[9630]: Stopped Mark boot as successful after the user session has run 2 minutes. Jan 10 10:31:43 hn-dlp systemd[9630]: Reached target Shutdown. Jan 10 10:31:43 hn-dlp systemd[9630]: Starting Exit the Session... Jan 10 10:31:43 hn-dlp systemd[1]: user@2002.service: Succeeded. Jan 10 10:31:43 hn-dlp systemd[1]: Stopped User Manager for UID 2002. Jan 10 10:31:43 hn-dlp systemd[1]: Stopping /run/user/2002 mount wrapper... Jan 10 10:31:43 hn-dlp systemd[1]: Removed slice User Slice of UID 2002. Jan 10 10:31:43 hn-dlp systemd[2804]: run-user-2002.mount: Succeeded. Jan 10 10:31:43 hn-dlp systemd[1]: run-user-2002.mount: Succeeded. Jan 10 10:31:43 hn-dlp systemd[1]: user-runtime-dir@2002.service: Succeeded. Jan 10 10:31:43 hn-dlp systemd[1]: Stopped /run/user/2002 mount wrapper. Jan 10 10:31:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:32:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:32:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 95. Jan 10 10:32:03 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:32:03 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:32:05 hn-dlp platform-python[9916]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:32:05 hn-dlp platform-python[9916]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:32:05 hn-dlp platform-python[9916]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:32:06 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9916]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:32:06 hn-dlp ipa-ods-exporter[9916]: Traceback (most recent call last): Jan 10 10:32:06 hn-dlp ipa-ods-exporter[9916]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:32:06 hn-dlp ipa-ods-exporter[9916]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:32:06 hn-dlp ipa-ods-exporter[9916]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:32:06 hn-dlp ipa-ods-exporter[9916]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:32:06 hn-dlp ipa-ods-exporter[9916]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:32:06 hn-dlp ipa-ods-exporter[9916]: h = self.p11.import_public_key(**params) Jan 10 10:32:06 hn-dlp ipa-ods-exporter[9916]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:32:06 hn-dlp ipa-ods-exporter[9916]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:32:06 hn-dlp ipa-ods-exporter[9916]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:32:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:32:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:33:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:33:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 96. Jan 10 10:33:06 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:33:06 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:33:08 hn-dlp platform-python[9926]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:33:08 hn-dlp platform-python[9926]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:33:08 hn-dlp platform-python[9926]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:33:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9926]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:33:09 hn-dlp ipa-ods-exporter[9926]: Traceback (most recent call last): Jan 10 10:33:09 hn-dlp ipa-ods-exporter[9926]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:33:09 hn-dlp ipa-ods-exporter[9926]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:33:09 hn-dlp ipa-ods-exporter[9926]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:33:09 hn-dlp ipa-ods-exporter[9926]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:33:09 hn-dlp ipa-ods-exporter[9926]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:33:09 hn-dlp ipa-ods-exporter[9926]: h = self.p11.import_public_key(**params) Jan 10 10:33:09 hn-dlp ipa-ods-exporter[9926]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:33:09 hn-dlp ipa-ods-exporter[9926]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:33:09 hn-dlp ipa-ods-exporter[9926]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:33:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:33:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:33:19 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:33:19 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:33:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:34:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:34:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 97. Jan 10 10:34:09 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:34:09 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:34:11 hn-dlp platform-python[9935]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:34:11 hn-dlp platform-python[9935]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:34:11 hn-dlp platform-python[9935]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:34:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9935]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:34:12 hn-dlp ipa-ods-exporter[9935]: Traceback (most recent call last): Jan 10 10:34:12 hn-dlp ipa-ods-exporter[9935]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:34:12 hn-dlp ipa-ods-exporter[9935]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:34:12 hn-dlp ipa-ods-exporter[9935]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:34:12 hn-dlp ipa-ods-exporter[9935]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:34:12 hn-dlp ipa-ods-exporter[9935]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:34:12 hn-dlp ipa-ods-exporter[9935]: h = self.p11.import_public_key(**params) Jan 10 10:34:12 hn-dlp ipa-ods-exporter[9935]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:34:12 hn-dlp ipa-ods-exporter[9935]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:34:12 hn-dlp ipa-ods-exporter[9935]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:34:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:34:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:35:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:35:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 98. Jan 10 10:35:12 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:35:12 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:35:14 hn-dlp platform-python[9946]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:35:14 hn-dlp platform-python[9946]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:35:14 hn-dlp platform-python[9946]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:35:15 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9946]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:35:15 hn-dlp ipa-ods-exporter[9946]: Traceback (most recent call last): Jan 10 10:35:15 hn-dlp ipa-ods-exporter[9946]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:35:15 hn-dlp ipa-ods-exporter[9946]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:35:15 hn-dlp ipa-ods-exporter[9946]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:35:15 hn-dlp ipa-ods-exporter[9946]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:35:15 hn-dlp ipa-ods-exporter[9946]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:35:15 hn-dlp ipa-ods-exporter[9946]: h = self.p11.import_public_key(**params) Jan 10 10:35:15 hn-dlp ipa-ods-exporter[9946]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:35:15 hn-dlp ipa-ods-exporter[9946]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:35:15 hn-dlp ipa-ods-exporter[9946]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:35:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:35:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:35:19 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:35:19 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:35:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:36:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:36:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 99. Jan 10 10:36:15 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:36:15 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:36:18 hn-dlp platform-python[9956]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:36:18 hn-dlp platform-python[9956]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:36:18 hn-dlp platform-python[9956]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:36:18 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9956]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:36:18 hn-dlp ipa-ods-exporter[9956]: Traceback (most recent call last): Jan 10 10:36:18 hn-dlp ipa-ods-exporter[9956]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:36:18 hn-dlp ipa-ods-exporter[9956]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:36:18 hn-dlp ipa-ods-exporter[9956]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:36:18 hn-dlp ipa-ods-exporter[9956]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:36:18 hn-dlp ipa-ods-exporter[9956]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:36:18 hn-dlp ipa-ods-exporter[9956]: h = self.p11.import_public_key(**params) Jan 10 10:36:18 hn-dlp ipa-ods-exporter[9956]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:36:18 hn-dlp ipa-ods-exporter[9956]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:36:18 hn-dlp ipa-ods-exporter[9956]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:36:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:36:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:37:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:37:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 100. Jan 10 10:37:18 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:37:18 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:37:19 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:37:19 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:37:21 hn-dlp platform-python[9965]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:37:21 hn-dlp platform-python[9965]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:37:21 hn-dlp platform-python[9965]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:37:21 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9965]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:37:21 hn-dlp ipa-ods-exporter[9965]: Traceback (most recent call last): Jan 10 10:37:21 hn-dlp ipa-ods-exporter[9965]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:37:21 hn-dlp ipa-ods-exporter[9965]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:37:21 hn-dlp ipa-ods-exporter[9965]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:37:21 hn-dlp ipa-ods-exporter[9965]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:37:21 hn-dlp ipa-ods-exporter[9965]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:37:21 hn-dlp ipa-ods-exporter[9965]: h = self.p11.import_public_key(**params) Jan 10 10:37:21 hn-dlp ipa-ods-exporter[9965]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:37:21 hn-dlp ipa-ods-exporter[9965]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:37:21 hn-dlp ipa-ods-exporter[9965]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:37:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:37:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:37:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:38:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:38:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 101. Jan 10 10:38:21 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:38:21 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:38:24 hn-dlp platform-python[9973]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:38:24 hn-dlp platform-python[9973]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:38:24 hn-dlp platform-python[9973]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:38:24 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9973]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:38:24 hn-dlp ipa-ods-exporter[9973]: Traceback (most recent call last): Jan 10 10:38:24 hn-dlp ipa-ods-exporter[9973]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:38:24 hn-dlp ipa-ods-exporter[9973]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:38:24 hn-dlp ipa-ods-exporter[9973]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:38:24 hn-dlp ipa-ods-exporter[9973]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:38:24 hn-dlp ipa-ods-exporter[9973]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:38:24 hn-dlp ipa-ods-exporter[9973]: h = self.p11.import_public_key(**params) Jan 10 10:38:24 hn-dlp ipa-ods-exporter[9973]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:38:24 hn-dlp ipa-ods-exporter[9973]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:38:24 hn-dlp ipa-ods-exporter[9973]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:38:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:38:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:39:19 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:39:19 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:39:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:39:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 102. Jan 10 10:39:24 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:39:24 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:39:27 hn-dlp platform-python[9983]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:39:27 hn-dlp platform-python[9983]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:39:27 hn-dlp platform-python[9983]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:39:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9983]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:39:27 hn-dlp ipa-ods-exporter[9983]: Traceback (most recent call last): Jan 10 10:39:27 hn-dlp ipa-ods-exporter[9983]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:39:27 hn-dlp ipa-ods-exporter[9983]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:39:27 hn-dlp ipa-ods-exporter[9983]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:39:27 hn-dlp ipa-ods-exporter[9983]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:39:27 hn-dlp ipa-ods-exporter[9983]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:39:27 hn-dlp ipa-ods-exporter[9983]: h = self.p11.import_public_key(**params) Jan 10 10:39:27 hn-dlp ipa-ods-exporter[9983]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:39:27 hn-dlp ipa-ods-exporter[9983]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:39:27 hn-dlp ipa-ods-exporter[9983]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:39:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:39:27 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:39:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:40:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:40:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 103. Jan 10 10:40:28 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:40:28 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:40:30 hn-dlp platform-python[9992]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:40:30 hn-dlp platform-python[9992]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:40:30 hn-dlp platform-python[9992]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:40:30 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[9992]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:40:30 hn-dlp ipa-ods-exporter[9992]: Traceback (most recent call last): Jan 10 10:40:30 hn-dlp ipa-ods-exporter[9992]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:40:30 hn-dlp ipa-ods-exporter[9992]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:40:30 hn-dlp ipa-ods-exporter[9992]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:40:30 hn-dlp ipa-ods-exporter[9992]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:40:30 hn-dlp ipa-ods-exporter[9992]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:40:30 hn-dlp ipa-ods-exporter[9992]: h = self.p11.import_public_key(**params) Jan 10 10:40:30 hn-dlp ipa-ods-exporter[9992]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:40:30 hn-dlp ipa-ods-exporter[9992]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:40:30 hn-dlp ipa-ods-exporter[9992]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:40:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:40:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:41:19 hn-dlp named-pkcs11[7597]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 10:41:19 hn-dlp named-pkcs11[7597]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:41:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:41:31 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 104. Jan 10 10:41:31 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:41:31 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:41:33 hn-dlp platform-python[10002]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:41:33 hn-dlp platform-python[10002]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:41:33 hn-dlp platform-python[10002]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:41:34 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[10002]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:41:34 hn-dlp ipa-ods-exporter[10002]: Traceback (most recent call last): Jan 10 10:41:34 hn-dlp ipa-ods-exporter[10002]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:41:34 hn-dlp ipa-ods-exporter[10002]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:41:34 hn-dlp ipa-ods-exporter[10002]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:41:34 hn-dlp ipa-ods-exporter[10002]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:41:34 hn-dlp ipa-ods-exporter[10002]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:41:34 hn-dlp ipa-ods-exporter[10002]: h = self.p11.import_public_key(**params) Jan 10 10:41:34 hn-dlp ipa-ods-exporter[10002]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:41:34 hn-dlp ipa-ods-exporter[10002]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:41:34 hn-dlp ipa-ods-exporter[10002]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:41:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:41:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:41:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:42:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:42:34 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 105. Jan 10 10:42:34 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:42:34 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:42:37 hn-dlp platform-python[10012]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:42:37 hn-dlp platform-python[10012]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:42:37 hn-dlp platform-python[10012]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:42:37 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[10012]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:42:37 hn-dlp ipa-ods-exporter[10012]: Traceback (most recent call last): Jan 10 10:42:37 hn-dlp ipa-ods-exporter[10012]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:42:37 hn-dlp ipa-ods-exporter[10012]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:42:37 hn-dlp ipa-ods-exporter[10012]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:42:37 hn-dlp ipa-ods-exporter[10012]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:42:37 hn-dlp ipa-ods-exporter[10012]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:42:37 hn-dlp ipa-ods-exporter[10012]: h = self.p11.import_public_key(**params) Jan 10 10:42:37 hn-dlp ipa-ods-exporter[10012]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:42:37 hn-dlp ipa-ods-exporter[10012]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:42:37 hn-dlp ipa-ods-exporter[10012]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:42:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:42:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:43:19 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:43:19 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:43:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:43:37 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 106. Jan 10 10:43:37 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:43:37 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:43:40 hn-dlp platform-python[10020]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:43:40 hn-dlp platform-python[10020]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:43:40 hn-dlp platform-python[10020]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:43:40 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[10020]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:43:40 hn-dlp ipa-ods-exporter[10020]: Traceback (most recent call last): Jan 10 10:43:40 hn-dlp ipa-ods-exporter[10020]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:43:40 hn-dlp ipa-ods-exporter[10020]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:43:40 hn-dlp ipa-ods-exporter[10020]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:43:40 hn-dlp ipa-ods-exporter[10020]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:43:40 hn-dlp ipa-ods-exporter[10020]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:43:40 hn-dlp ipa-ods-exporter[10020]: h = self.p11.import_public_key(**params) Jan 10 10:43:40 hn-dlp ipa-ods-exporter[10020]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:43:40 hn-dlp ipa-ods-exporter[10020]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:43:40 hn-dlp ipa-ods-exporter[10020]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:43:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:43:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:43:56 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:44:26 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.Setroubleshootd' requested by ':1.48' (uid=0 pid=677 comm="/usr/sbin/sedispatch " label="system_u:system_r:auditd_t:s0") (using servicehelper) Jan 10 10:44:26 hn-dlp dbus-daemon[10115]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 10:44:27 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.Setroubleshootd' Jan 10 10:44:27 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.483' (uid=995 pid=10115 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 10:44:27 hn-dlp dbus-daemon[10127]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 10:44:28 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 10:44:30 hn-dlp setroubleshoot[10115]: SELinux is preventing /usr/libexec/platform-python3.6 from getattr access on the file /usr/sbin/kpatch. For complete SELinux messages run: sealert -l 5cda8d58-1349-4feb-8b4b-5d3fe096a952 Jan 10 10:44:30 hn-dlp setroubleshoot[10115]: SELinux is preventing /usr/libexec/platform-python3.6 from getattr access on the file /usr/sbin/kpatch.#012#012***** Plugin catchall (100. confidence) suggests **************************#012#012If you believe that platform-python3.6 should be allowed getattr access on the kpatch file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'rhsmcertd-worke' --raw | audit2allow -M my-rhsmcertdworke#012# semodule -X 300 -i my-rhsmcertdworke.pp#012 Jan 10 10:44:40 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.483' (uid=995 pid=10115 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 10:44:40 hn-dlp dbus-daemon[10136]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 10:44:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:44:40 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 107. Jan 10 10:44:40 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:44:40 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:44:41 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 10:44:43 hn-dlp setroubleshoot[10115]: SELinux is preventing rhsmcertd-worke from execute access on the file kpatch. For complete SELinux messages run: sealert -l 684ea0a4-d817-4204-9a20-c69257d26cfb Jan 10 10:44:43 hn-dlp setroubleshoot[10115]: SELinux is preventing rhsmcertd-worke from execute access on the file kpatch.#012#012***** Plugin catchall (100. confidence) suggests **************************#012#012If you believe that rhsmcertd-worke should be allowed execute access on the kpatch file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'rhsmcertd-worke' --raw | audit2allow -M my-rhsmcertdworke#012# semodule -X 300 -i my-rhsmcertdworke.pp#012 Jan 10 10:44:50 hn-dlp platform-python[10137]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:44:51 hn-dlp platform-python[10137]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:44:51 hn-dlp platform-python[10137]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:44:51 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[10137]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:44:51 hn-dlp ipa-ods-exporter[10137]: Traceback (most recent call last): Jan 10 10:44:51 hn-dlp ipa-ods-exporter[10137]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:44:51 hn-dlp ipa-ods-exporter[10137]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:44:51 hn-dlp ipa-ods-exporter[10137]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:44:51 hn-dlp ipa-ods-exporter[10137]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:44:51 hn-dlp ipa-ods-exporter[10137]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:44:51 hn-dlp ipa-ods-exporter[10137]: h = self.p11.import_public_key(**params) Jan 10 10:44:51 hn-dlp ipa-ods-exporter[10137]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:44:51 hn-dlp ipa-ods-exporter[10137]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:44:51 hn-dlp ipa-ods-exporter[10137]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:44:51 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:44:51 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:44:52 hn-dlp dbus-daemon[710]: [system] Activating service name='org.fedoraproject.SetroubleshootPrivileged' requested by ':1.483' (uid=995 pid=10115 comm="/usr/libexec/platform-python -Es /usr/sbin/setroub" label="system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023") (using servicehelper) Jan 10 10:44:52 hn-dlp dbus-daemon[10169]: [system] Failed to reset fd limit before activating service: org.freedesktop.DBus.Error.AccessDenied: Failed to restore old fd limit: Operation not permitted Jan 10 10:44:53 hn-dlp dbus-daemon[710]: [system] Successfully activated service 'org.fedoraproject.SetroubleshootPrivileged' Jan 10 10:44:55 hn-dlp setroubleshoot[10115]: SELinux is preventing rhsmcertd-worke from read access on the file container-tools.module. For complete SELinux messages run: sealert -l bb37e6ed-51d9-407e-8b19-3b95ed2f0fd2 Jan 10 10:44:55 hn-dlp setroubleshoot[10115]: SELinux is preventing rhsmcertd-worke from read access on the file container-tools.module.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow daemons to dump core#012Then you must tell SELinux about this by enabling the 'daemons_dump_core' boolean.#012#012Do#012setsebool -P daemons_dump_core 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that rhsmcertd-worke should be allowed read access on the container-tools.module file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'rhsmcertd-worke' --raw | audit2allow -M my-rhsmcertdworke#012# semodule -X 300 -i my-rhsmcertdworke.pp#012 Jan 10 10:44:56 hn-dlp setroubleshoot[10115]: SELinux is preventing rhsmcertd-worke from read access on the file container-tools.module. For complete SELinux messages run: sealert -l bb37e6ed-51d9-407e-8b19-3b95ed2f0fd2 Jan 10 10:44:56 hn-dlp setroubleshoot[10115]: SELinux is preventing rhsmcertd-worke from read access on the file container-tools.module.#012#012***** Plugin catchall_boolean (89.3 confidence) suggests ******************#012#012If you want to allow daemons to dump core#012Then you must tell SELinux about this by enabling the 'daemons_dump_core' boolean.#012#012Do#012setsebool -P daemons_dump_core 1#012#012***** Plugin catchall (11.6 confidence) suggests **************************#012#012If you believe that rhsmcertd-worke should be allowed read access on the container-tools.module file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'rhsmcertd-worke' --raw | audit2allow -M my-rhsmcertdworke#012# semodule -X 300 -i my-rhsmcertdworke.pp#012 Jan 10 10:45:19 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:45:19 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:45:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:45:52 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 108. Jan 10 10:45:52 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:45:52 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:45:56 hn-dlp platform-python[10178]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:45:56 hn-dlp platform-python[10178]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:45:56 hn-dlp platform-python[10178]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:45:56 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[10178]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:45:56 hn-dlp ipa-ods-exporter[10178]: Traceback (most recent call last): Jan 10 10:45:56 hn-dlp ipa-ods-exporter[10178]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:45:56 hn-dlp ipa-ods-exporter[10178]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:45:56 hn-dlp ipa-ods-exporter[10178]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:45:56 hn-dlp ipa-ods-exporter[10178]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:45:56 hn-dlp ipa-ods-exporter[10178]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:45:56 hn-dlp ipa-ods-exporter[10178]: h = self.p11.import_public_key(**params) Jan 10 10:45:56 hn-dlp ipa-ods-exporter[10178]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:45:56 hn-dlp ipa-ods-exporter[10178]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:45:56 hn-dlp ipa-ods-exporter[10178]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:45:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:45:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:45:57 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:46:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:46:56 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 109. Jan 10 10:46:56 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:46:56 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:46:59 hn-dlp platform-python[10187]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:46:59 hn-dlp platform-python[10187]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:46:59 hn-dlp platform-python[10187]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:46:59 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[10187]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:46:59 hn-dlp ipa-ods-exporter[10187]: Traceback (most recent call last): Jan 10 10:46:59 hn-dlp ipa-ods-exporter[10187]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:46:59 hn-dlp ipa-ods-exporter[10187]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:46:59 hn-dlp ipa-ods-exporter[10187]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:46:59 hn-dlp ipa-ods-exporter[10187]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:46:59 hn-dlp ipa-ods-exporter[10187]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:46:59 hn-dlp ipa-ods-exporter[10187]: h = self.p11.import_public_key(**params) Jan 10 10:46:59 hn-dlp ipa-ods-exporter[10187]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:46:59 hn-dlp ipa-ods-exporter[10187]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:46:59 hn-dlp ipa-ods-exporter[10187]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:46:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:46:59 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:47:19 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:47:19 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:47:57 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:48:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:48:00 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 110. Jan 10 10:48:00 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:48:00 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:48:02 hn-dlp platform-python[10198]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:48:02 hn-dlp platform-python[10198]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:48:02 hn-dlp platform-python[10198]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:48:02 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[10198]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:48:02 hn-dlp ipa-ods-exporter[10198]: Traceback (most recent call last): Jan 10 10:48:02 hn-dlp ipa-ods-exporter[10198]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:48:02 hn-dlp ipa-ods-exporter[10198]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:48:02 hn-dlp ipa-ods-exporter[10198]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:48:02 hn-dlp ipa-ods-exporter[10198]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:48:02 hn-dlp ipa-ods-exporter[10198]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:48:02 hn-dlp ipa-ods-exporter[10198]: h = self.p11.import_public_key(**params) Jan 10 10:48:02 hn-dlp ipa-ods-exporter[10198]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:48:02 hn-dlp ipa-ods-exporter[10198]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:48:02 hn-dlp ipa-ods-exporter[10198]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:48:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:48:02 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:49:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:49:03 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 111. Jan 10 10:49:03 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:49:03 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:49:05 hn-dlp platform-python[10207]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:49:05 hn-dlp platform-python[10207]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:49:05 hn-dlp platform-python[10207]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:49:05 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[10207]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:49:05 hn-dlp ipa-ods-exporter[10207]: Traceback (most recent call last): Jan 10 10:49:05 hn-dlp ipa-ods-exporter[10207]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:49:05 hn-dlp ipa-ods-exporter[10207]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:49:05 hn-dlp ipa-ods-exporter[10207]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:49:05 hn-dlp ipa-ods-exporter[10207]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:49:05 hn-dlp ipa-ods-exporter[10207]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:49:05 hn-dlp ipa-ods-exporter[10207]: h = self.p11.import_public_key(**params) Jan 10 10:49:05 hn-dlp ipa-ods-exporter[10207]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:49:05 hn-dlp ipa-ods-exporter[10207]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:49:05 hn-dlp ipa-ods-exporter[10207]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:49:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:49:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:49:19 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:49:19 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:49:57 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:50:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:50:06 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 112. Jan 10 10:50:06 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:50:06 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:50:08 hn-dlp platform-python[10220]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:50:08 hn-dlp platform-python[10220]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:50:08 hn-dlp platform-python[10220]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:50:09 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[10220]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:50:09 hn-dlp ipa-ods-exporter[10220]: Traceback (most recent call last): Jan 10 10:50:09 hn-dlp ipa-ods-exporter[10220]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:50:09 hn-dlp ipa-ods-exporter[10220]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:50:09 hn-dlp ipa-ods-exporter[10220]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:50:09 hn-dlp ipa-ods-exporter[10220]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:50:09 hn-dlp ipa-ods-exporter[10220]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:50:09 hn-dlp ipa-ods-exporter[10220]: h = self.p11.import_public_key(**params) Jan 10 10:50:09 hn-dlp ipa-ods-exporter[10220]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:50:09 hn-dlp ipa-ods-exporter[10220]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:50:09 hn-dlp ipa-ods-exporter[10220]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:50:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:50:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:51:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:51:09 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 113. Jan 10 10:51:09 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:51:09 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:51:11 hn-dlp platform-python[10229]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:51:11 hn-dlp platform-python[10229]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:51:11 hn-dlp platform-python[10229]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:51:12 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[10229]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:51:12 hn-dlp ipa-ods-exporter[10229]: Traceback (most recent call last): Jan 10 10:51:12 hn-dlp ipa-ods-exporter[10229]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:51:12 hn-dlp ipa-ods-exporter[10229]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:51:12 hn-dlp ipa-ods-exporter[10229]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:51:12 hn-dlp ipa-ods-exporter[10229]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:51:12 hn-dlp ipa-ods-exporter[10229]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:51:12 hn-dlp ipa-ods-exporter[10229]: h = self.p11.import_public_key(**params) Jan 10 10:51:12 hn-dlp ipa-ods-exporter[10229]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:51:12 hn-dlp ipa-ods-exporter[10229]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:51:12 hn-dlp ipa-ods-exporter[10229]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:51:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:51:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:51:19 hn-dlp named-pkcs11[7597]: no valid RRSIG resolving '19.172.in-addr.arpa/DS/IN': 8.8.8.8#53 Jan 10 10:51:19 hn-dlp named-pkcs11[7597]: no valid DS resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:51:57 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:52:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:52:12 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 114. Jan 10 10:52:12 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:52:12 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:52:14 hn-dlp platform-python[10238]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:52:14 hn-dlp platform-python[10238]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:52:14 hn-dlp platform-python[10238]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:52:15 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[10238]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:52:15 hn-dlp ipa-ods-exporter[10238]: Traceback (most recent call last): Jan 10 10:52:15 hn-dlp ipa-ods-exporter[10238]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:52:15 hn-dlp ipa-ods-exporter[10238]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:52:15 hn-dlp ipa-ods-exporter[10238]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:52:15 hn-dlp ipa-ods-exporter[10238]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:52:15 hn-dlp ipa-ods-exporter[10238]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:52:15 hn-dlp ipa-ods-exporter[10238]: h = self.p11.import_public_key(**params) Jan 10 10:52:15 hn-dlp ipa-ods-exporter[10238]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:52:15 hn-dlp ipa-ods-exporter[10238]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:52:15 hn-dlp ipa-ods-exporter[10238]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:52:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:52:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:53:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:53:15 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 115. Jan 10 10:53:15 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:53:15 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:53:18 hn-dlp platform-python[10248]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:53:18 hn-dlp platform-python[10248]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:53:18 hn-dlp platform-python[10248]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:53:18 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[10248]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:53:18 hn-dlp ipa-ods-exporter[10248]: Traceback (most recent call last): Jan 10 10:53:18 hn-dlp ipa-ods-exporter[10248]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:53:18 hn-dlp ipa-ods-exporter[10248]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:53:18 hn-dlp ipa-ods-exporter[10248]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:53:18 hn-dlp ipa-ods-exporter[10248]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:53:18 hn-dlp ipa-ods-exporter[10248]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:53:18 hn-dlp ipa-ods-exporter[10248]: h = self.p11.import_public_key(**params) Jan 10 10:53:18 hn-dlp ipa-ods-exporter[10248]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:53:18 hn-dlp ipa-ods-exporter[10248]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:53:18 hn-dlp ipa-ods-exporter[10248]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:53:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:53:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:53:19 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:53:19 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:53:57 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:54:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:54:18 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 116. Jan 10 10:54:18 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:54:18 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:54:21 hn-dlp platform-python[10257]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:54:21 hn-dlp platform-python[10257]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:54:21 hn-dlp platform-python[10257]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:54:21 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[10257]: new replica keys in LDAP: {'0x8cd9a2579a1b2f741ad3420ed0291a18', '0xbb3d905d65b56247a74eeda39285b6b6'} Jan 10 10:54:21 hn-dlp ipa-ods-exporter[10257]: Traceback (most recent call last): Jan 10 10:54:21 hn-dlp ipa-ods-exporter[10257]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:54:21 hn-dlp ipa-ods-exporter[10257]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:54:21 hn-dlp ipa-ods-exporter[10257]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:54:21 hn-dlp ipa-ods-exporter[10257]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:54:21 hn-dlp ipa-ods-exporter[10257]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:54:21 hn-dlp ipa-ods-exporter[10257]: h = self.p11.import_public_key(**params) Jan 10 10:54:21 hn-dlp ipa-ods-exporter[10257]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:54:21 hn-dlp ipa-ods-exporter[10257]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:54:21 hn-dlp ipa-ods-exporter[10257]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:54:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:54:21 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:55:19 hn-dlp named-pkcs11[7597]: validating 1.191.19.172.in-addr.arpa/PTR: bad cache hit (19.172.in-addr.arpa/DS) Jan 10 10:55:19 hn-dlp named-pkcs11[7597]: broken trust chain resolving '1.191.19.172.in-addr.arpa/PTR/IN': 8.8.8.8#53 Jan 10 10:55:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:55:22 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 117. Jan 10 10:55:22 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:55:22 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:55:24 hn-dlp platform-python[10266]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:55:24 hn-dlp platform-python[10266]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:55:24 hn-dlp platform-python[10266]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:55:24 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[10266]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:55:24 hn-dlp ipa-ods-exporter[10266]: Traceback (most recent call last): Jan 10 10:55:24 hn-dlp ipa-ods-exporter[10266]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:55:24 hn-dlp ipa-ods-exporter[10266]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:55:24 hn-dlp ipa-ods-exporter[10266]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:55:24 hn-dlp ipa-ods-exporter[10266]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:55:24 hn-dlp ipa-ods-exporter[10266]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:55:24 hn-dlp ipa-ods-exporter[10266]: h = self.p11.import_public_key(**params) Jan 10 10:55:24 hn-dlp ipa-ods-exporter[10266]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:55:24 hn-dlp ipa-ods-exporter[10266]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:55:24 hn-dlp ipa-ods-exporter[10266]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:55:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:55:24 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'. Jan 10 10:55:57 hn-dlp puppet-agent[784]: The CRL issued by 'CN=Certificate Authority,O=IPA.example.local' has expired, verify time is synchronized Jan 10 10:56:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Service RestartSec=1min expired, scheduling restart. Jan 10 10:56:25 hn-dlp systemd[1]: ipa-ods-exporter.service: Scheduled restart job, restart counter is at 118. Jan 10 10:56:25 hn-dlp systemd[1]: Stopped IPA OpenDNSSEC Signer replacement. Jan 10 10:56:25 hn-dlp systemd[1]: Started IPA OpenDNSSEC Signer replacement. Jan 10 10:56:27 hn-dlp platform-python[10276]: Configuration.cpp(96): Missing log.level in configuration. Using default value: INFO Jan 10 10:56:27 hn-dlp platform-python[10276]: Configuration.cpp(96): Missing slots.mechanisms in configuration. Using default value: ALL Jan 10 10:56:27 hn-dlp platform-python[10276]: Configuration.cpp(124): Missing slots.removable in configuration. Using default value: false Jan 10 10:56:27 hn-dlp /usr/libexec/ipa/ipa-ods-exporter[10276]: new replica keys in LDAP: {'0xbb3d905d65b56247a74eeda39285b6b6', '0x8cd9a2579a1b2f741ad3420ed0291a18'} Jan 10 10:56:27 hn-dlp ipa-ods-exporter[10276]: Traceback (most recent call last): Jan 10 10:56:27 hn-dlp ipa-ods-exporter[10276]: File "/usr/libexec/ipa/ipa-ods-exporter", line 701, in <module> Jan 10 10:56:27 hn-dlp ipa-ods-exporter[10276]: ldap2master_replica_keys_sync(ldapkeydb, localhsm) Jan 10 10:56:27 hn-dlp ipa-ods-exporter[10276]: File "/usr/libexec/ipa/ipa-ods-exporter", line 304, in ldap2master_replica_keys_sync Jan 10 10:56:27 hn-dlp ipa-ods-exporter[10276]: localhsm.import_public_key(new_key_ldap, new_key_ldap['ipapublickey']) Jan 10 10:56:27 hn-dlp ipa-ods-exporter[10276]: File "/usr/lib/python3.6/site-packages/ipaserver/dnssec/localhsm.py", line 183, in import_public_key Jan 10 10:56:27 hn-dlp ipa-ods-exporter[10276]: h = self.p11.import_public_key(**params) Jan 10 10:56:27 hn-dlp ipa-ods-exporter[10276]: File "/usr/lib/python3.6/site-packages/ipaserver/p11helper.py", line 1451, in import_public_key Jan 10 10:56:27 hn-dlp ipa-ods-exporter[10276]: raise DuplicationError("Public key with same ID already exists") Jan 10 10:56:27 hn-dlp ipa-ods-exporter[10276]: ipaserver.p11helper.DuplicationError: Public key with same ID already exists Jan 10 10:56:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Main process exited, code=exited, status=1/FAILURE Jan 10 10:56:28 hn-dlp systemd[1]: ipa-ods-exporter.service: Failed with result 'exit-code'.
This issue tracker is only used for tracking development issues. For operational problems please use freeipa-users@ mailing list instead.
Metadata Update from @abbra: - Issue close_status updated to: invalid - Issue status updated to: Closed (was: Open)